CVE-2021-24005 is a high-severity vulnerability affecting FortiAuthenticator versions prior to 6.3.0, stemming from the use of hard-coded cryptographic keys. This flaw allows an attacker with access to configuration files or the command-line interface to decrypt sensitive data due to knowledge of the fixed key. With a CVSS score of 7.5, it presents a high confidentiality impact with low attack complexity and no user interaction required. There is currently no evidence of active exploitation, nor are there public exploit codes or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.3.0CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.