FG-IR-24-111: LDAP Clear-text credentials retrievable with IP modification
An insufficiently protected credentials [CWE-522] vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-111?
The severity of FG-IR-24-111 is classified as high due to the potential for credential retrieval by an attacker.
How do I fix FG-IR-24-111?
To fix FG-IR-24-111, update FortiOS to a patched version as recommended by Fortinet.
What versions of FortiOS are affected by FG-IR-24-111?
FG-IR-24-111 affects FortiOS versions 6.4, 7.0, 7.2, and 7.4.
Can an attacker exploit FG-IR-24-111 remotely?
Yes, an attacker with access to the FortiOS configuration can exploit FG-IR-24-111 remotely by modifying the LDAP server IP address.
What are the risks associated with FG-IR-24-111?
The risks associated with FG-IR-24-111 include unauthorized retrieval of LDAP credentials, which can lead to further system exploitation.