SB2021120720 - Information disclosure in FortiSandbox, FortiWeb and FortiADC
Published: December 7, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Required Cryptographic Step (CVE-ID: CVE-2021-32591)
The vulnerability allows an attacker to compromise users' passwords.
The vulnerability exists due to missing cryptographic steps in the function that encrypts users' LDAP and RADIUS credentials. An attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
Remediation
Install update from vendor's website.