FG-IR-24-326: Exposure of sensitive information in RADIUS Accounting-Request
Published Jan 14, 2025
·Updated
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
Affected Software
2 affected componentsFixes available
Fortinet FortiOS=.
Fortinet FortiOS>=7.4.0<=7.4.4
Event History
Jan 14, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-326?
The severity of FG-IR-24-326 is significant due to the potential exposure of sensitive information.
2
How do I fix FG-IR-24-326?
To fix FG-IR-24-326, upgrade FortiOS to version 7.6.1 or higher, or to version 7.4.5 if you are on 7.4.0 to 7.4.4.
3
What type of vulnerability is FG-IR-24-326?
FG-IR-24-326 is an insertion of sensitive information into sent data vulnerability as defined by CWE-201.
4
Who is affected by FG-IR-24-326?
FG-IR-24-326 affects users of FortiOS versions prior to 7.6.1 and from 7.4.0 to 7.4.4.
5
What can an attacker do with FG-IR-24-326?
An attacker can intercept RADIUS accounting requests and retrieve the shared secret due to FG-IR-24-326.