Weak password storage
Summary
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC may allow an attacker with access to the database to perform attacks to recover the passwords.
Affected Products
FortiNAC version 9.4.0
FortiNAC version 9.2.0 through 9.2.5
FortiNAC version 9.1.0 through 9.1.7
FortiNAC 8.8 all versions
FortiNAC 8.7 all versions
FortiNAC 8.6 all versions
FortiNAC 8.5 all versions
FortiNAC 8.3 all versions
FortiNAC 7.2 all versions are not affected
Solutions
Please upgrade to FortiNAC-F version 7.2.0 or above
Please upgrade to FortiNAC version 9.4.1 or above
Please upgrade to FortiNAC version 9.2.6 or above
Please upgrade to FortiNAC version 9.1.8 or above
Acknowledgement
Internally discovered by Gwendal Guégniaud from Fortinet Product Security Team.Timeline
2023-02-16: Initial publication