CVE-2021-41030

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/12/2021
Last modified:
10/12/2021

Description

An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.9 (including)
cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.4 (including)
cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlient_enterprise_management_server:7.0.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools