PT-2021-21160 · Fortinet · Fortisdnconnector

Published

2021-10-06

·

Updated

2021-10-14

·

CVE-2021-36178

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiSDNConnector versions 1.1.7 and below
Description The issue allows an attacker to disclose third-party devices' credential information via a configuration page lookup due to insufficiently protected credentials.
Recommendations For Fortinet FortiSDNConnector versions 1.1.7 and below, consider restricting access to the configuration page to minimize the risk of credential disclosure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36178

Affected Products

Fortisdnconnector