CVE-2021-24005

MEDIUM

FortiAuthenticator < 6.3.0 - Hard-coded Cryptographic Key Exposure

Title source: llm
STIX 2.1

Description

Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-20-049

Scores

CVSS v3 4.0
EPSS 0.0013
EPSS Percentile 31.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
fortinet/fortiauthenticator 6.0.0 - 6.3.0
Published Jul 06, 2021
Tracked Since Feb 18, 2026