First published: Tue Nov 02 2021(Updated: )
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSIEM | >=3.1.0<=4.1.4 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-41023.
The title of the vulnerability is 'Unprotected Storage of Credentials in Fortinet FortiSIEM Windows Agent'.
The severity level of CVE-2021-41023 is medium with a score of 5.5.
Fortinet FortiSIEM Windows Agent version 4.1.4 and below are affected.
An authenticated user can exploit this vulnerability by reading the plaintext credential storage in log files, allowing them to disclose the agent password.