First published: Wed Jun 02 2021(Updated: )
An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | >=6.4.0<6.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24012 is classified as a high severity vulnerability due to the potential for unauthorized SSLVPN access.
To fix CVE-2021-24012, upgrade FortiGate to versions 6.4.5 or later.
CVE-2021-24012 affects users of FortiGate running FortiOS versions 6.4.0 to 6.4.4.
CVE-2021-24012 allows LDAP users to connect via SSLVPN with any certificate from a trusted Certificate Authority, potentially bypassing authentication.
CVE-2021-24012 was disclosed in early 2021.