CVE-2021-41019: Missing certificate CN/SAN validation leads to information disclosure
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
Other sources
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-41019.
What is the title of the vulnerability?
The title of the vulnerability is 'An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions...'
What is the severity of CVE-2021-41019?
The severity of CVE-2021-41019 is medium with a severity value of 6.5.
Which software versions are affected by CVE-2021-41019?
FortiOS versions 6.4.6 and below are affected by CVE-2021-41019.
How does CVE-2021-41019 exploit the vulnerability?
CVE-2021-41019 exploits the vulnerability by allowing the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.