CVE-2016-7542: Infoleak
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7542?
CVE-2016-7542 is considered to be of medium severity due to its potential to expose sensitive password hashes for non-super-admins.
Who is affected by CVE-2016-7542?
CVE-2016-7542 affects Fortinet devices running FortiOS versions 5.2.x prior to 5.2.10 and 5.4.x prior to 5.4.2.
How do I fix CVE-2016-7542?
To mitigate CVE-2016-7542, upgrade your Fortinet FortiOS to versions 5.2.10 or 5.4.2 or later.
What type of access does CVE-2016-7542 provide to attackers?
CVE-2016-7542 allows read-only administrators to access read-write administrators' password hashes, potentially enabling them to crack these hashes.
Is CVE-2016-7542 a privilege escalation vulnerability?
CVE-2016-7542 is not a privilege escalation vulnerability but instead involves improper access control for password hash exposure.