CVE-2021-22124
published 2021-08-04CVE-2021-22124: An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.02%
59.4th percentile
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiauthenticator | — | — |
| fortinet | fortiauthenticator | 4.0.0 – 4.3.4 | — |
| fortinet | fortiauthenticator | 5.0.0 – 5.5.0 | — |
| fortinet | fortiauthenticator | >= 6.0.0 < 6.0.6 | 6.0.6 |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | >= 3.0.0 < 3.0.7 | 3.0.7 |
| fortinet | fortisandbox | >= 3.1.0 < 3.1.5 | 3.1.5 |
| fortinet | fortisandbox | >= 3.2.0 < 3.2.2 | 3.2.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xfq8-42vh-gcw4: An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3
ghsa_unreviewed·2022-05-24
CVE-2021-22124 [HIGH] CWE-400 GHSA-xfq8-42vh-gcw4: An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
Fortinet
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 throug...
vendor_fortinet·2021-08-04·CVSS 7.5
CVE-2021-22124 [HIGH] CWE-400 An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 throug...
FG-IR-20-170: An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 throug...
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
CVEs: CVE-2021-22124
CWEs: CWE-400
CVSS: 7.5 (high)
Affected products: FortiAuthenticator, FortiSandbox
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-04
Published