PT-2021-6858 · Fortinet · Fortios
Published
2021-09-13
·
Updated
2021-11-04
·
CVE-2021-41019
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 6.4.6 and below
Description
The issue is related to an improper validation of certificate with host mismatch, which may allow the connection to a malicious LDAP server via options in the GUI. This could lead to the disclosure of sensitive information, such as AD credentials. The vulnerability is associated with insufficient verification of the certificate's CN/SAN, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations
For FortiOS versions 6.4.6 and below, update to a version above 6.4.6 to resolve the issue.
As a temporary workaround, consider restricting access to the LDAP server options in the GUI to minimize the risk of exploitation.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios