CVE-2021-24012: High severity fortios vulnerability
Published Jun 2, 2021
·Updated
An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.
Affected Software
1 affected component
Fortinet FortiOS>=6.4.0<6.4.5
Event History
Jun 2, 2021
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24012?
CVE-2021-24012 is classified as a high severity vulnerability due to the potential for unauthorized SSLVPN access.
2
How do I fix CVE-2021-24012?
To fix CVE-2021-24012, upgrade FortiGate to versions 6.4.5 or later.
3
Who is affected by CVE-2021-24012?
CVE-2021-24012 affects users of FortiGate running FortiOS versions 6.4.0 to 6.4.4.
4
What impacts does CVE-2021-24012 have on security?
CVE-2021-24012 allows LDAP users to connect via SSLVPN with any certificate from a trusted Certificate Authority, potentially bypassing authentication.
5
When was CVE-2021-24012 disclosed?
CVE-2021-24012 was disclosed in early 2021.