CVE-2021-44166
published 2022-03-02CVE-2021-44166: An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker…
PriorityP419medium4.1CVSS 3.1
AVNACLPRLUIRSCCNILAN
EPSS
0.64%
46.2th percentile
An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortitokenandroid | — | — |
| fortinet | fortitoken | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitoken_mobile | — | — |
| fortinet | fortitokenmobile | — | — |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and...
vendor_fortinet·2022-03-02·CVSS 4.1
CVE-2021-44166 [MEDIUM] An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and...
FG-IR-21-210: An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and...
An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.
CVEs: CVE-2021-44166
CVSS: 4.1 (medium)
Affected products: FortiToken, FortiTokenmobile
GHSA
GHSA-7w6m-4c3c-jjv3: An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5
ghsa_unreviewed·2022-03-03
CVE-2021-44166 [MEDIUM] GHSA-7w6m-4c3c-jjv3: An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5
An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-02
Published