CVE-2021-36171: Weak RNG
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-36171.
What is the severity of CVE-2021-36171?
The severity of CVE-2021-36171 is high.
What is the affected software for CVE-2021-36171?
The affected software for CVE-2021-36171 is Fortinet FortiPortal versions up to and including 6.0.6.
What is the description of CVE-2021-36171?
CVE-2021-36171 is a vulnerability that allows a remote unauthenticated attacker to predict parts or the whole newly generated password in the password reset feature of FortiPortal before version 6.0.6 due to the use of a weak pseudo-random number generator.
Is there a fix available for CVE-2021-36171?
Yes, a fix is available for CVE-2021-36171. It is recommended to update FortiPortal to version 6.0.6 or later to address this vulnerability.