PT-2021-6858 · Fortinet · Fortios

Published

2021-09-13

·

Updated

2021-11-04

·

CVE-2021-41019

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 6.4.6 and below
Description The issue is related to an improper validation of certificate with host mismatch, which may allow the connection to a malicious LDAP server via options in the GUI. This could lead to the disclosure of sensitive information, such as AD credentials. The vulnerability is associated with insufficient verification of the certificate's CN/SAN, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations For FortiOS versions 6.4.6 and below, update to a version above 6.4.6 to resolve the issue. As a temporary workaround, consider restricting access to the LDAP server options in the GUI to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02334
CVE-2021-41019

Affected Products

Fortios