Vulnerability record · CVE-2021-24005 · published 6 July 2021
CVE-2021-24005: Fortinet fortiauthenticator hard-coded credentials vulnerability
Fortinet · Fortiauthenticator
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.
Description
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/psirt/FG-IR-20-049 | Vendor Advisory |
| https://fortiguard.com/psirt/FG-IR-20-049 | Vendor Advisory |
Track CVE-2021-24005 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24005), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.