Use of a Broken or Risky Cryptographic Algorithm

Summary

A use of a broken or risky cryptographic algorithm [CWE-327] in FortiSIEM may allow a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.

Version Affected Solution
FortiSIEM 7.0 Not affected Not Applicable
FortiSIEM 6.7 6.7.0 through 6.7.1 Upgrade to 6.7.2 or above
FortiSIEM 6.6 6.6 all versions Migrate to a fixed release
FortiSIEM 6.5 6.5 all versions Migrate to a fixed release
FortiSIEM 6.4 6.4 all versions Migrate to a fixed release
FortiSIEM 6.3 6.3 all versions Migrate to a fixed release
FortiSIEM 6.2 6.2 all versions Migrate to a fixed release
FortiSIEM 6.1 6.1 all versions Migrate to a fixed release
FortiSIEM 5.4 5.4 all versions Migrate to a fixed release
FortiSIEM 5.3 5.3 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu and Austin Stark of Fortinet Product Security team.

Timeline

2023-06-12: Initial publication