Lucene search

K
cvelistFortinetCVELIST:CVE-2021-22128
HistoryMar 04, 2021 - 5:27 p.m.

CVE-2021-22128

2021-03-0417:27:43
fortinet
www.cve.org
2
fortiproxy
ssl vpn
access control
vulnerability
remote attacker
zebos shell

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

35.3%

An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.

CNA Affected

[
  {
    "product": "Fortinet FortiProxy",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiProxy 2.0.0, 1.2.9 and below"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

35.3%

Related for CVELIST:CVE-2021-22128