First published: Wed Apr 06 2022(Updated: )
A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWan | <4.5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26113.
The title of the vulnerability is 'A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9'.
The severity of CVE-2021-26113 is high, with a severity value of 7.5.
CVE-2021-26113 affects FortiWAN versions before 4.5.9, allowing an attacker with access to the password file to potentially guess stored passwords.
To fix the vulnerability, update FortiWAN to version 4.5.9 or later.