CVE-2021-41020: High severity fortinet fortiisolator vulnerability
Published May 4, 2022
·Updated
An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL.
Affected Software
1 affected component
Fortinet FortiIsolator>=2.3.0<2.3.3
Event History
May 4, 2022
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41020.
2
What is the severity of CVE-2021-41020?
The severity of CVE-2021-41020 is high, with a severity value of 8.8.
3
Which software versions are affected by CVE-2021-41020?
FortiIsolator versions 2.3.2 and below are affected by CVE-2021-41020.
4
How does the vulnerability CVE-2021-41020 manifest?
The vulnerability CVE-2021-41020 manifests as an improper access control vulnerability, allowing an authenticated, non-privileged attacker to regenerate the CA certificate via the regeneration URL.
5
Is there any fix available for CVE-2021-41020?
To mitigate the vulnerability CVE-2021-41020, users should update to FortiIsolator version 2.3.3 or later.