QID 377740
QID 377740: FortiMail - Missing Cryptographic Steps Vulnerability (FG-IR-20-222)
A missing cryptographic steps vulnerability [CWE-325] in the function that encrypts users' LDAP and RADIUS credentials in FortiMail may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
Affected Products:
FortiMail versions 7.0.1 and below.
FortiMail versions 6.4.5 and below.
FortiMail versions 6.2.7 and below.
FortiMail versions 6.0.11 and below.
All FortiMail versions 5.x.
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiMail.
Vulnerable version may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-20-222
- FG-IR-20-222 -
www.fortiguard.com/psirt/FG-IR-20-222
CVEs related to QID 377740
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-222 |
|