CVE-2021-22131
published 2022-07-18CVE-2021-22131: A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below…
PriorityP424medium5.4CVSS 3.1
AVAACHPRNUIRSUCHILAN
EPSS
0.14%
3.5th percentile
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitokenandroid | — | — |
| fortinet | fortitokenios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9f5-mqv7-56mh: A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5
ghsa_unreviewed·2022-07-19
CVE-2021-22131 [MEDIUM] CWE-295 GHSA-q9f5-mqv7-56mh: A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.
Fortinet
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet...
vendor_fortinet·2022-07-18·CVSS 6.4
CVE-2021-22131 [MEDIUM] CWE-295 A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet...
FG-IR-21-024: A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet...
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.
CVEs: CVE-2021-22131
CWEs: CWE-295
CVSS: 6.4 (medium)
Affected products: FortiTokenAndroid, FortiTokenWinApp, FortiTokeniOS, FortiTokenmobile, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-18
Published