CVE-2016-7542: Fortinet FortiOS
Medium severity, CVSS 4.9. EPSS: 1.5% chance of exploitation in the next 30 days.
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
Affected products
- Fortinet FortiOS: version 5.2.0 only; version 5.2.1 only; version 5.2.2 only; version 5.2.3 only; version 5.2.4 only; version 5.2.5 only; …
Published 2017-03-30. Last modified 2026-06-17.