CVE-2021-26113: High severity fortinet fortiwan vulnerability
Published Apr 6, 2022
·Updated
A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.
Affected Software
1 affected component
Fortinet FortiWan<4.5.9
Event History
Apr 6, 2022
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-26113.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9'.
3
What is the severity of CVE-2021-26113?
The severity of CVE-2021-26113 is high, with a severity value of 7.5.
4
How does CVE-2021-26113 affect FortiWAN?
CVE-2021-26113 affects FortiWAN versions before 4.5.9, allowing an attacker with access to the password file to potentially guess stored passwords.
5
How can I fix the vulnerability in FortiWAN?
To fix the vulnerability, update FortiWAN to version 4.5.9 or later.