FortiWAN - Use of hardcoded salt for password hashing


A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.

Affected Products

FortiWAN version 4.5.8 and below.


Upgrade to FortiWAN version 4.5.9 or above.


Internally reported and discovered by Giuseppe Cocomazzi of Fortinet Product Security team.