PT-2022-10488 · Fortinet · Fortiauthenticator Ha Service

Published

2022-02-02

·

Updated

2022-07-12

·

CVE-2021-36177

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiAuthenticator HA service versions 6.3.2 and below FortiAuthenticator HA service versions 6.2.x FortiAuthenticator HA service versions 6.1.x FortiAuthenticator HA service versions 6.0.x
Description An improper access control issue may allow an attacker on the same VLAN as the HA management interface to make an unauthenticated direct connection to the FAC's database. This could potentially be exploited by an attacker to access sensitive data without proper authorization.
Recommendations For FortiAuthenticator HA service versions 6.3.2 and below, consider restricting access to the HA management interface to minimize the risk of exploitation. For FortiAuthenticator HA service versions 6.2.x, restrict access to the HA management interface until a patch is available. For FortiAuthenticator HA service versions 6.1.x, limit access to the FAC's database to prevent unauthenticated connections. For FortiAuthenticator HA service versions 6.0.x, apply configuration changes to enforce proper access control on the HA management interface.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-36177

Affected Products

Fortiauthenticator Ha Service