CVE-2021-44166
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/03/2022
Last modified:
11/03/2022
Description
An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.
Impact
Base Score 3.x
4.10
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:fortinet:fortitoken_mobile:4.0.0:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:4.0.1:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:4.1.1:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:4.2.1:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:4.2.2:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:4.3.0:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:4.4.0:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:4.5.0:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:5.0.2:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:5.0.3:*:*:*:*:android:*:* | ||
cpe:2.3:a:fortinet:fortitoken_mobile:5.1.0:*:*:*:*:android:*:* |
To consult the complete list of CPE names with products and versions, see this page