Lucene search

K
cveFortinetCVE-2021-22128
HistoryMar 04, 2021 - 6:15 p.m.

CVE-2021-22128

2021-03-0418:15:13
fortinet
web.nvd.nist.gov
26
cve-2021-22128
fortiproxy
ssl vpn
access control
vulnerability
remote attacker
zebos shell
quick connection
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

35.3%

An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.

Affected configurations

Nvd
Node
fortinetfortiproxyRange1.2.9
OR
fortinetfortiproxyMatch2.0.0
VendorProductVersionCPE
fortinetfortiproxy*cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
fortinetfortiproxy2.0.0cpe:2.3:a:fortinet:fortiproxy:2.0.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Fortinet FortiProxy",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiProxy 2.0.0, 1.2.9 and below"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

35.3%

Related for CVE-2021-22128