CVE-2021-36177

An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-20-217 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

07 Feb 2022, 13:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 3.3
v3 : 4.3
CWE CWE-863
CPE cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*
First Time Fortinet fortiauthenticator
Fortinet
References (CONFIRM) https://fortiguard.com/psirt/FG-IR-20-217 - (CONFIRM) https://fortiguard.com/psirt/FG-IR-20-217 - Vendor Advisory

02 Feb 2022, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-02 11:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-36177

Mitre link : CVE-2021-36177

CVE.ORG link : CVE-2021-36177


JSON object : View

Products Affected

fortinet

  • fortiauthenticator