CVE-2021-22124: Uncontrolled Resource Consumption (Denial of Service) in login module
An uncontrolled resource consumption (denial of service) vulnerability in FortiSandbox and FortiAuthenticator login modules may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
Other sources
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiSandbox and FortiAuthenticator vulnerability?
The vulnerability ID for this FortiSandbox and FortiAuthenticator vulnerability is CVE-2021-22124.
What is the severity of CVE-2021-22124?
The severity of CVE-2021-22124 is high with a severity value of 7.5.
What software versions are affected by CVE-2021-22124?
FortiSandbox versions 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6, as well as FortiAuthenticator versions before 6.0.6 are affected by CVE-2021-22124.
How does CVE-2021-22124 impact FortiSandbox and FortiAuthenticator?
CVE-2021-22124 can allow an unauthenticated attacker to bring the device into an unresponsive state through an uncontrolled resource consumption (denial of service) vulnerability in the login modules.
Is there a reference for CVE-2021-22124?
Yes, you can find more information about CVE-2021-22124 at the following reference: https://fortiguard.com/advisory/FG-IR-20-170