An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-20-217 | Vendor Advisory |
Configurations
Information
Published : 2022-02-02 03:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-36177
Mitre link : CVE-2021-36177
JSON object : View
CWE
Products Affected
fortinet
- fortiauthenticator