CVE-2021-36177

An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:13

Type Values Removed Values Added
CVSS v2 : 3.3
v3 : 4.3
v2 : 3.3
v3 : 4.2
References () https://fortiguard.com/psirt/FG-IR-20-217 - Vendor Advisory () https://fortiguard.com/psirt/FG-IR-20-217 - Vendor Advisory

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

07 Feb 2022, 13:56

Type Values Removed Values Added
References (CONFIRM) https://fortiguard.com/psirt/FG-IR-20-217 - (CONFIRM) https://fortiguard.com/psirt/FG-IR-20-217 - Vendor Advisory
CWE CWE-863
CPE cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 3.3
v3 : 4.3

02 Feb 2022, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-02 11:15

Updated : 2024-11-21 06:13


NVD link : CVE-2021-36177

Mitre link : CVE-2021-36177

CVE.ORG link : CVE-2021-36177


JSON object : View

Products Affected

fortinet

  • fortiauthenticator