Low severity1.8NVD Advisory· Published Jun 11, 2024· Updated Jun 17, 2026
CVE-2024-21754
CVE-2024-21754
Description
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.0.14
- (no CPE)range: <=7.4.2, all versions of 7.2, all versions of 7.0, all versions of 2.0
- (no CPE)range: 7.4.0
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-23-423nvdVendor Advisory
News mentions
0No linked articles in our index yet.