Medium severity4.9NVD Advisory· Published Mar 30, 2017· Updated May 13, 2026
CVE-2016-7542
CVE-2016-7542
Description
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
Affected products
13cpe:2.3:o:fortinet:fortios:5.2.0:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:o:fortinet:fortios:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.1:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.2:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.3:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.4:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.5:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.6:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.7:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.8:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.2.9:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:5.4.1:*:*:*:*:*:*:*
- (no CPE)range: 5.2.0 - 5.2.9, 5.4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/94690nvdThird Party AdvisoryVDB Entry
- fortiguard.com/advisory/FG-IR-16-050nvdNot Applicable
- www.securitytracker.com/id/1037394nvd
News mentions
0No linked articles in our index yet.