cbcvebase.
CVE-2021-22131
published 2022-07-18

CVE-2021-22131: A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below…

PriorityP424medium5.4CVSS 3.1
AVAACHPRNUIRSUCHILAN
EPSS
0.14%
3.5th percentile
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitoken_mobile
fortinetfortitokenandroid
fortinetfortitokenios
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.