We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2016-7542



Description

A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.

Reserved 2016-09-09 | Published 2017-03-30 | Updated 2024-10-25 | Assigner fortinet

Problem types

Information leak

Product status

5.2.0 - 5.2.9, 5.4.1
affected

References

www.securityfocus.com/bid/94690 (94690) vdb-entry

fortiguard.com/advisory/FG-IR-16-050

www.securitytracker.com/id/1037394 (1037394) vdb-entry

cve.org (CVE-2016-7542)

nvd.nist.gov (CVE-2016-7542)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2016-7542

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.