CVE-2024-21754
CVSS V2 None
CVSS V3 None
Description
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
Overview
- CVE ID
- CVE-2024-21754
- Assigner
- fortinet
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-11T14:32:01.335Z
- Last Modified Date
- 2024-06-11T16:13:16.539Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-423 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-21754 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21754 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 15:27:50 | Added to TrackCVE |