PT-2021-7519 · Fortinet · Fortiisolator

Published

2021-09-13

·

Updated

2022-07-12

·

CVE-2021-41020

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiIsolator versions 2.3.2 and below
Description The issue is related to improper access control, allowing an authenticated, non-privileged attacker to regenerate the CA certificate via a specific URL, potentially leading to unauthorized access to protected information.
Recommendations For versions 2.3.2 and below, consider restricting access to the CA certificate regeneration URL as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-07202
CVE-2021-41020

Affected Products

Fortiisolator