FG-IR-24-094: Use of Hard-coded Cryptographic Key to encrypt sensitive data
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-094?
FG-IR-24-094 is a critical vulnerability due to its potential to expose encrypted sensitive data.
How do I fix FG-IR-24-094?
To mitigate FG-IR-24-094, upgrade FortiManager to version 7.6.2 or later, or to versions 7.4.6, 7.2.10, or applicable updates as recommended.
Which versions of FortiManager are affected by FG-IR-24-094?
FortiManager versions between 7.6.0 and 7.6.1, 7.4.0 and 7.4.5, and 7.2.0 and 7.2.9 are impacted by FG-IR-24-094.
Can FG-IR-24-094 affect FortiManager Cloud services?
Yes, FortiManager Cloud versions between 7.4.1 and 7.4.5, as well as 7.2.1 and 7.2.8, are subject to FG-IR-24-094.
What kind of access is needed to exploit FG-IR-24-094?
Exploitation of FG-IR-24-094 requires JSON API access permissions, allowing an attacker to potentially decrypt sensitive data.