CVE-2024-32122
A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.
Scoring
- Severity
- LOW
- CVSS base score
- 2.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:C
- EPSS probability
- 0.22%
- CWE
- CWE-257
- Published
- 2025-04-08
- Last modified
- 2026-08-11
Affected products
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
Weakness type
Related vulnerabilities
- CVE-2026-20128 — Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
- CVE-2025-8904 — Privilege escalation issue in Amazon EMR Secret Agent component
- CVE-2025-6996 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2025-6995 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2019-3736 — Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM
- CVE-2022-34838 — ABB Ability TM Operations Data Management Zenon Zenon Log Server file access control
- CVE-2022-32519 — A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE