← back
CVE-2024-21754lowobserved exploitationCWE-916

CVE-2024-21754

30Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 1.7epss 3.5%
from disclosure to weapon
Published on NVDJun 11
VulnCheck+2d
exploitation probability
3.5%top 11% of all CVEs
observed exploitation
yesVulnCheck
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N/E:F/RL:X/RC:R