5.4

CVE-2021-22131

A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortitoken Mobile Version 0.4.10 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 0.4.20 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 3.0.0 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 3.0.0 SwPlatform windows
Fortinet ≫ Fortitoken Mobile Version 3.0.1 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 3.0.1 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 3.0.1 SwPlatform windows
Fortinet ≫ Fortitoken Mobile Version 3.0.2 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 3.0.2 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 3.0.3 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 3.0.3 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 3.0.4 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 3.0.4 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 3.0.5 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 4.0.0 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 4.0.1 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 4.0.3 SwPlatform windows
Fortinet ≫ Fortitoken Mobile Version 4.1.0 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 4.1.1 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 4.1.1 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 4.2.0 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 4.2.1 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 4.2.2 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 4.3.0 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 4.3.0 SwPlatform ios
Fortinet ≫ Fortitoken Mobile Version 4.4.0 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 4.5.0 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 5.0.2 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 5.0.3 SwPlatform android
Fortinet ≫ Fortitoken Mobile Version 5.2.0 SwPlatform ios
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.039
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 1.2 4.2
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Fortinet 6.4 1.2 5.2
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://fortiguard.com/advisory/FG-IR-21-024
Patch
Vendor Advisory