CVE-2024-21754

LOW EXPLOITED

FortiProxy 2.0.0-2.0.13 and FortiOS 6.4.0-6.4.14 - Use of Password Hash With Insufficient Computational Effort

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-21754 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including CyberSecuritist.

AI-analyzed exploit summary The repository claims to provide an exploit for CVE-2024-21754 but lacks actual exploit code, instead directing users to an external download link. The README contains vague descriptions and no technical details about the vulnerability or exploit mechanics.

Description

A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.

Exploits (1)

nomisec SUSPICIOUS 4 stars
by CyberSecuritist · poc
https://github.com/CyberSecuritist/CVE-2024-21754-Forti-RCE

The repository claims to provide an exploit for CVE-2024-21754 but lacks actual exploit code, instead directing users to an external download link. The README contains vague descriptions and no technical details about the vulnerability or exploit mechanics.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: FortiOS and FortiProxy
Auth required
Prerequisites: super-admin privileges · CLI access
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 1.8
EPSS 0.0347
EPSS Percentile 87.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2024-06-13
CWE
CWE-916
Status published
Products (2)
fortinet/fortios 6.4.0 - 6.4.15
fortinet/fortiproxy 2.0.0 - 2.0.14
Published Jun 11, 2024
Tracked Since Feb 18, 2026