CVE-2021-36177: Medium severity fortinet fortiauthenticator vulnerability
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36177?
CVE-2021-36177 is an improper access control vulnerability in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x.
How does CVE-2021-36177 affect FortiAuthenticator?
CVE-2021-36177 allows an attacker on the same VLAN as the HA management interface to make an unauthenticated direct connection to the FortiAuthenticator's database.
What is the severity of CVE-2021-36177?
CVE-2021-36177 has a severity level of medium.
How can I fix CVE-2021-36177?
To fix CVE-2021-36177, upgrade FortiAuthenticator to version 6.3.3 or apply the necessary patches provided by Fortinet.
Where can I find more information about CVE-2021-36177?
You can find more information about CVE-2021-36177 on the FortiGuard Advisory page: https://fortiguard.com/psirt/FG-IR-20-217