Lucene search

K
cvelistFortinetCVELIST:CVE-2021-36171
HistoryMar 01, 2022 - 6:05 p.m.

CVE-2021-36171

2022-03-0118:05:10
fortinet
www.cve.org
4
cve-2021-36171
fortiportal
password reset
weak random number generator
remote attacker
unauthenticated

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

70.5%

The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.

CNA Affected

[
  {
    "product": "Fortinet FortiPortal",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiPortal before 6.0.6"
      }
    ]
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

70.5%

Related for CVELIST:CVE-2021-36171