CVE-2021-22128

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/03/2021
Last modified:
12/07/2022

Description

An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 1.2.9 (including)
cpe:2.3:a:fortinet:fortiproxy:2.0.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools