Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9cj-q2hj-hfq9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

EPSS

Процентиль: 97%
0.45022
Средний

9.8 Critical

CVSS3

Дефекты

CWE-178
CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость операционной системы FortiOS, связанная с недостатками процедуры аутентификации, позволяющая нарушителю войти в систему без запроса второго фактора аутентификации

EPSS

Процентиль: 97%
0.45022
Средний

9.8 Critical

CVSS3

Дефекты

CWE-178
CWE-287