First published: Tue Apr 08 2025(Updated: )
An insufficiently protected credentials [CWE-522] vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server.
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | >=7.4 | |
FortiOS | >=7.2 | |
FortiOS | >=7.0 | |
FortiOS | >=6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-111 is classified as high due to the potential for credential retrieval by an attacker.
To fix FG-IR-24-111, update FortiOS to a patched version as recommended by Fortinet.
FG-IR-24-111 affects FortiOS versions 6.4, 7.0, 7.2, and 7.4.
Yes, an attacker with access to the FortiOS configuration can exploit FG-IR-24-111 remotely by modifying the LDAP server IP address.
The risks associated with FG-IR-24-111 include unauthorized retrieval of LDAP credentials, which can lead to further system exploitation.