An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-20-217 | Vendor Advisory |
https://fortiguard.com/psirt/FG-IR-20-217 | Vendor Advisory |
Configurations
History
21 Nov 2024, 06:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/psirt/FG-IR-20-217 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 3.3
v3 : 4.2 |
Information
Published : 2022-02-02 11:15
Updated : 2024-11-21 06:13
NVD link : CVE-2021-36177
Mitre link : CVE-2021-36177
CVE.ORG link : CVE-2021-36177
JSON object : View
Products Affected
fortinet
- fortiauthenticator
CWE