CVE-2024-46665: Exposure of sensitive information in RADIUS Accounting-Request
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
Other sources
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46665?
CVE-2024-46665 has a high severity rating due to the potential for sensitive information leakage.
How do I fix CVE-2024-46665?
To fix CVE-2024-46665, update FortiOS to version 7.6.1 or 7.4.5 and above.
What versions of FortiOS are affected by CVE-2024-46665?
FortiOS versions 7.4.0 through 7.4.4 and 7.6.0 are affected by CVE-2024-46665.
Who is impacted by CVE-2024-46665?
Organizations using the affected versions of FortiOS may be vulnerable to CVE-2024-46665.
What type of vulnerability is CVE-2024-46665?
CVE-2024-46665 is classified as an injection vulnerability that exposes sensitive information.