CVE detail
CVE-2024-21754 — CVE-2024-21754
Published 2024-06-11 · Modified 2026-06-17 · Vendor fortinet · Product fortiproxy · Source nvd
LOW
severity
CVSS-derived band
0.0347
EPSS probability
exploitation probability, 30d
88.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References