CVE-2021-41023: Medium severity fortinet fortisiem windows agent vulnerability
Published Nov 2, 2021
·Updated
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
Affected Software
2 affected components
Fortinet FortiSIEM>=3.1.0<=4.1.4
Microsoft Windows
Event History
Nov 2, 2021
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-41023.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Unprotected Storage of Credentials in Fortinet FortiSIEM Windows Agent'.
3
What is the severity level of CVE-2021-41023?
The severity level of CVE-2021-41023 is medium with a score of 5.5.
4
Which software versions are affected by this vulnerability?
Fortinet FortiSIEM Windows Agent version 4.1.4 and below are affected.
5
How can an authenticated user exploit this vulnerability?
An authenticated user can exploit this vulnerability by reading the plaintext credential storage in log files, allowing them to disclose the agent password.