QID 43918
Date Published: 2022-10-17
QID 43918: FortiOS Flaws Over krb Keytab Encryption Scheme (FG-IR-22-158)
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS may allow an attacker in possession of the encrypted file to decipher it.
Affected Products:
FortiOS version 7.2.0
FortiOS version 7.0.0 through 7.0.5
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.11
FortiOS version 6.0.0 through 6.0.15
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable version of FortiOS may allow an attacker in possession of the encrypted file to decipher it.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-158
Vendor References
- FG-IR-22-158 -
www.fortiguard.com/psirt/FG-IR-22-158
CVEs related to QID 43918
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-158 |
|