First published: Tue Nov 02 2021(Updated: )
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=6.4.0<=6.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-41019.
The title of the vulnerability is 'An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions...'
The severity of CVE-2021-41019 is medium with a severity value of 6.5.
FortiOS versions 6.4.6 and below are affected by CVE-2021-41019.
CVE-2021-41019 exploits the vulnerability by allowing the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.