CVE-2021-41019

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
02/11/2021
Last modified:
04/11/2021

Description

An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.6 (including)


References to Advisories, Solutions, and Tools