Exposure of sensitive information in RADIUS Accounting-Request

Summary

An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.

Version Affected Solution
FortiOS 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiOS 7.4 7.4.0 through 7.4.4 Upgrade to 7.4.5 or above
FortiOS 7.2 Not affected Not Applicable
FortiOS 7.0 Not affected Not Applicable
FortiOS 6.4 Not affected Not Applicable
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Workarounds:

  1. Use RADIUS over TLS
  2. Disable the RADIUS accounting-server feature

Acknowledgement

Fortinet is pleased to thank Mert Gülsoy from aionet.com.tr for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication