PSIRT Advisories

FortiWAN - Use of hardcoded salt for password hashing

Summary

A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.

Affected Products

FortiWAN version 4.5.8 and below.

Solutions

Upgrade to FortiWAN version 4.5.9 or above.

Acknowledgement

Internally reported and discovered by Giuseppe Cocomazzi of Fortinet Product Security team.