Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hx92-84x6-67mx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

EPSS

Процентиль: 99%
0.7127
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 6.5
nvd
около 6 лет назад

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость интерфейса командной строки (CLI) операционных систем FortiOS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 99%
0.7127
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-798