CVE-2021-24024: Medium severity fortinet fortiadc vulnerability
Published Apr 12, 2021
·Updated
A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to read other local users' password in log files.
Affected Software
2 affected components
Fortinet FortiADC<=5.3.7
Fortinet Fortiadc Manager<=5.3.0
Event History
Apr 12, 2021
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24024.
2
How does the vulnerability impact FortiADCManager and FortiADC?
The vulnerability allows a remote authenticated attacker to read other local users' passwords stored in log files.
3
What versions of FortiADCManager and FortiADC are affected?
FortiADCManager 5.3.0 and below, 5.2.1 and below, and FortiADC 5.3.7 and below are affected.
4
What is the severity of CVE-2021-24024?
The severity of CVE-2021-24024 is medium.
5
How can I fix the vulnerability in FortiADCManager and FortiADC?
It is recommended to upgrade FortiADCManager and FortiADC to versions that have addressed the vulnerability.