CVE-2021-36166

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
01/03/2022
Last modified:
12/07/2022

Description

An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 5.4.12 (including)
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.12 (excluding)
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.8 (excluding)
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.6 (excluding)
cpe:2.3:a:fortinet:fortimail:7.0.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools