PT-2021-15644 · Fortinet · Fortigate+1

Published

2021-06-01

·

Updated

2021-06-14

·

CVE-2021-24012

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: FortiGate versions 6.4.0 through 6.4.4
Description: The issue is related to an improper following of a certificate's chain of trust, which may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority. This could potentially lead to unauthorized access.
Recommendations: For FortiGate versions 6.4.0 through 6.4.4, update to a version that properly follows the certificate's chain of trust to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24012

Affected Products

Fortigate
Fortios