CVE-2016-7542: Fortinet FortiOS

Medium severity, CVSS 4.9. EPSS: 1.5% chance of exploitation in the next 30 days.

A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.

Affected products

  • Fortinet FortiOS: version 5.2.0 only; version 5.2.1 only; version 5.2.2 only; version 5.2.3 only; version 5.2.4 only; version 5.2.5 only; …

Published 2017-03-30. Last modified 2026-06-17.