A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94690 | third party advisory vdb entry |
http://fortiguard.com/advisory/FG-IR-16-050 | not applicable |
http://www.securitytracker.com/id/1037394 | vdb entry |