Flaws over keytab encryption scheme
Summary
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt keytab values in FortiOS & FortiProxy may allow an attacker in possession of the encrypted secret to decipher it.
Affected Products
FortiProxy 7.2 all versions are not affectedFortiProxy version 7.0.0 through 7.0.4
FortiProxy 2.0 all versions
FortiProxy 1.2 all versions
FortiProxy version 1.1.2 through 1.1.6
FortiProxy 1.0 all versions are not affected
At least
FortiOS version 7.2.0
FortiOS version 7.0.0 through 7.0.5
FortiOS version 6.4.0 through 6.4.14
FortiOS version 6.2.0 through 6.2.15
FortiOS version 6.0.0 through 6.0.17
Solutions
Upgrade to FortiOS version 7.2.1 or above.
Upgrade to FortiOS version 7.0.6 or above.
Upgrade to FortiProxy version 7.2.0 or above.
Upgrade to FortiProxy version 7.0.5 or above.