FG-IR-23-423: Weak key derivation for backup file
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS and FortiProxy may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-423?
The severity of FG-IR-23-423 is considered critical due to the potential for privileged attackers to decrypt backup files.
How do I fix FG-IR-23-423?
To fix FG-IR-23-423, upgrade to FortiOS version 7.4.4 or later, or FortiProxy version 7.4.3 or later.
Which versions of FortiOS are affected by FG-IR-23-423?
FortiOS versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.8, and earlier versions 7.0 and 6.4 are affected by FG-IR-23-423.
Which versions of FortiProxy are affected by FG-IR-23-423?
FortiProxy versions 7.4.0 to 7.4.2 and all earlier versions 7.0 and below are affected by FG-IR-23-423.
Who is vulnerable to exploitation of FG-IR-23-423?
Privileged attackers with super-admin profiles and CLI access are vulnerable to exploiting FG-IR-23-423.