Source |
Fortinet Vunerability |
Identifiant |
8648092 |
Date de publication |
2025-02-11 00:00:00 (vue: 2025-02-11 17:08:47) |
Titre |
Use of Hard-coded Cryptographic Key to encrypt sensitive data |
Texte |
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager may allow an attacker with JSON API access permissions to decrypt some secrets even if the \'private-data-encryption\' setting is enabled. Revised on 2025-02-11 00:00:00
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager may allow an attacker with JSON API access permissions to decrypt some secrets even if the \'private-data-encryption\' setting is enabled. Revised on 2025-02-11 00:00:00 |
Notes |
|
Envoyé |
Oui |
Condensat |
00:00:00 2025 321 access allow api attacker coded cryptographic cwe data decrypt enabled encrypt encryption even fortimanager hard json key may permissions private revised secrets sensitive setting some use vulnerability |
Tags |
Vulnerability
|
Stories |
|
Move |
|