Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24012

Опубликовано: 02 июн. 2021
Источник: nvd
CVSS3: 6.5
CVSS3: 7.3
CVSS2: 7.5
EPSS Низкий

Описание

An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Версия от 6.4.0 (включая) до 6.4.5 (исключая)

EPSS

Процентиль: 43%
0.00207
Низкий

6.5 Medium

CVSS3

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-295

Связанные уязвимости

github
больше 3 лет назад

An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.

EPSS

Процентиль: 43%
0.00207
Низкий

6.5 Medium

CVSS3

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-295