Medium severity5.3NVD Advisory· Published Dec 8, 2021· Updated Jun 17, 2026
CVE-2021-32591
CVE-2021-32591
Description
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
Affected products
16cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*range: >=5.0.0,<=5.4.4
- cpe:2.3:a:fortinet:fortiadc:6.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiadc:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: >=3.2.0,<=3.2.2
- cpe:2.3:a:fortinet:fortisandbox:4.0.0:*:*:*:*:*:*:*
- (no CPE)range: <4.0.1
- (no CPE)range: FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier
- Range: <6.2.1
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-222nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.