First published: Tue Nov 02 2021(Updated: )
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-21-074 is considered critical due to its potential to disclose sensitive information.
To fix FG-IR-21-074, update FortiOS to the latest version provided by Fortinet that addresses this vulnerability.
FG-IR-21-074 can lead to the exposure of sensitive information, including Active Directory credentials, if exploited.
FG-IR-21-074 affects Fortinet FortiOS systems without proper certificate validation.
Yes, FG-IR-21-074 can be exploited remotely through a malicious LDAP server connection.