Fortinet FortiMail security bypass | CVE-2021-36166
NAME
Fortinet FortiMail security bypass
- Platforms Affected:
Fortinet FortiMail 5.4.12
Fortinet FortiMail 6.4.5
Fortinet FortiMail 6.2.7
Fortinet FortiMail 7.0.0
Fortinet FortiMail 6.0.11 - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Bypass Security
DESCRIPTION
Fortinet FortiMail could allow a remote attacker to bypass security restrictions, caused by improper authentication. By observing certain system properties, an attacker could exploit this vulnerability to efficiently guess one administrative account’s authentication token.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Refer to FortiGuard Advisory FG-IR-21-028 for patch, upgrade or suggested workaround information. See References.
- Reference Link:
https://www.fortiguard.com/psirt/FG-IR-21-028 - Reference Link:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36166
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.