CVE-2024-33504: Use of Hard-coded Cryptographic Key to encrypt sensitive data
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.
Other sources
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33504?
CVE-2024-33504 has a high severity due to the potential for unauthorized decryption of sensitive data.
How do I fix CVE-2024-33504?
To fix CVE-2024-33504, upgrade FortiManager to the latest version that has addressed this vulnerability.
What versions of FortiManager are affected by CVE-2024-33504?
CVE-2024-33504 affects FortiManager versions 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, as well as all versions of 7.0 and 6.4.
What kind of access is required for an attacker to exploit CVE-2024-33504?
An attacker needs JSON API access permissions to exploit CVE-2024-33504 and decrypt sensitive information.
What type of vulnerability is CVE-2024-33504 classified as?
CVE-2024-33504 is classified as a use of hard-coded cryptographic key vulnerability under CWE-321.