PT-2021-16955 · Fortinet · Fortigate+2
Published
2021-12-07
·
Updated
2021-12-10
·
CVE-2021-26103
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiProxy versions 2.0.3 and below, 1.2.11 and below
FortiGate versions 7.0.0, 6.4.6 and below, 6.2.9 and below
Description
An insufficient verification of data authenticity vulnerability in the user interface of FortiProxy and FortiGate SSL VPN portal may allow a remote, unauthenticated attacker to conduct a cross-site request forgery (CSRF) attack. Only SSL VPN in web mode or full mode are impacted by this vulnerability.
Recommendations
For FortiProxy versions 2.0.3 and below, consider disabling the SSL VPN portal in web mode or full mode until a patch is available.
For FortiProxy version 1.2.11 and below, consider disabling the SSL VPN portal in web mode or full mode until a patch is available.
For FortiGate versions 7.0.0, 6.4.6 and below, 6.2.9 and below, consider disabling the SSL VPN portal in web mode or full mode until a patch is available.
As a temporary workaround, restrict access to the SSL VPN portal to minimize the risk of exploitation.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortigate
Fortiproxy
Fortios