CVE-2024-32122
Last modified
CVE-2024-32122 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | >= 6.4.0, <= 6.4.16 |
| Fortinet | Fortios | >= 7.0.0, <= 7.0.17 |
| Fortinet | Fortios | >= 7.2.0, <= 7.2.11 |
| Fortinet | Fortios | >= 7.4.0, <= 7.4.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-32122?
How severe is CVE-2024-32122?
How do I fix CVE-2024-32122?
Are you affected by CVE-2024-32122?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
