CVE-2021-41019
published 2021-11-02CVE-2021-41019: An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.55%
42.2th percentile
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 6.4.0 – 6.4.6 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may...
vendor_fortinet·2021-11-02·CVSS 3.5
CVE-2021-41019 [LOW] CWE-295 An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may...
FG-IR-21-074: An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may...
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
CVEs: CVE-2021-41019
CWEs: CWE-295
CVSS: 3.5 (low)
Affected products: FortiOS
GHSA
GHSA-hj73-5q9f-3jj4: An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6
ghsa_unreviewed·2022-05-24
CVE-2021-41019 [MEDIUM] CWE-295 GHSA-hj73-5q9f-3jj4: An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-02
Published