CVE-2024-21754: Weak key derivation for backup file
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS and FortiProxy may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
Other sources
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability identified by CVE-2024-21754?
CVE-2024-21754 is a use of password hash with insufficient computational effort vulnerability that may allow a privileged attacker to decrypt backup files on FortiOS and FortiProxy.
What software versions are affected by CVE-2024-21754?
CVE-2024-21754 affects FortiOS versions 6.4 to 7.4.3 and FortiProxy versions 2.0 to 7.4.2.
How do I remediate the vulnerability CVE-2024-21754?
To fix CVE-2024-21754, upgrade FortiOS to version 7.4.4 or above and FortiProxy to version 7.4.3 or above.
Who is impacted by CVE-2024-21754?
Any organization using vulnerable versions of FortiOS or FortiProxy with super-admin profile and CLI access is at risk due to CVE-2024-21754.
What potential impacts does CVE-2024-21754 pose to my systems?
CVE-2024-21754 could allow an attacker to gain unauthorized access to sensitive backup files, leading to data breaches.