6.4

CVE-2021-22131

A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.

Data is provided by the National Vulnerability Database (NVD)
FortinetFortitoken Mobile Version0.4.10 SwPlatformandroid
FortinetFortitoken Mobile Version0.4.20 SwPlatformandroid
FortinetFortitoken Mobile Version3.0.0 SwPlatformandroid
FortinetFortitoken Mobile Version3.0.0 SwPlatformwindows
FortinetFortitoken Mobile Version3.0.1 SwPlatformandroid
FortinetFortitoken Mobile Version3.0.1 SwPlatformios
FortinetFortitoken Mobile Version3.0.1 SwPlatformwindows
FortinetFortitoken Mobile Version3.0.2 SwPlatformandroid
FortinetFortitoken Mobile Version3.0.2 SwPlatformios
FortinetFortitoken Mobile Version3.0.3 SwPlatformandroid
FortinetFortitoken Mobile Version3.0.3 SwPlatformios
FortinetFortitoken Mobile Version3.0.4 SwPlatformandroid
FortinetFortitoken Mobile Version3.0.4 SwPlatformios
FortinetFortitoken Mobile Version3.0.5 SwPlatformios
FortinetFortitoken Mobile Version4.0.0 SwPlatformandroid
FortinetFortitoken Mobile Version4.0.1 SwPlatformandroid
FortinetFortitoken Mobile Version4.0.3 SwPlatformwindows
FortinetFortitoken Mobile Version4.1.0 SwPlatformios
FortinetFortitoken Mobile Version4.1.1 SwPlatformandroid
FortinetFortitoken Mobile Version4.1.1 SwPlatformios
FortinetFortitoken Mobile Version4.2.0 SwPlatformios
FortinetFortitoken Mobile Version4.2.1 SwPlatformandroid
FortinetFortitoken Mobile Version4.2.2 SwPlatformandroid
FortinetFortitoken Mobile Version4.3.0 SwPlatformandroid
FortinetFortitoken Mobile Version4.3.0 SwPlatformios
FortinetFortitoken Mobile Version4.4.0 SwPlatformandroid
FortinetFortitoken Mobile Version4.5.0 SwPlatformandroid
FortinetFortitoken Mobile Version5.0.2 SwPlatformandroid
FortinetFortitoken Mobile Version5.0.3 SwPlatformandroid
FortinetFortitoken Mobile Version5.2.0 SwPlatformios
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.133
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 1.2 4.2
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
psirt@fortinet.com 6.4 1.2 5.2
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.