CVE-2021-32591
CVE-2021-32591
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
08 Dec 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:X/RC:X
Affected products
Fortinet · Fortinet FortiSandboxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →