QID 376676
Date Published: 2022-07-20
QID 376676: FortiMail Administrative Authentication Bypass Vulnerability (FG-IR-21-028)
Fortimail provides a platform having powerful, integrated capabilities to prevent, detect, and respond to email-based threats flexible deployment options to address on-premises, cloud, and hybrid email use cases
An improper authentication vulnerability in FortiMail may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
Affected Version
Fortimail Versions: 7.0.0, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2,6.0.11, 6.0.10, 6.0.1, 6.0.0, 5.4.9, 5.4.8, 5.4.7, 5.4.6, 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.12, 5.4.11, 5.4.10, 5.4.1, 5.4.0
QID Detection Logic(Authenticated):
QID will fire the command to get system status and will match the affected version
A successful exploit may lead to impacting confidentiality, integrity and availability
Customers are advised to refer to FG-IR-21-028 for more information.
- FG-IR-21-028 -
www.fortiguard.com/psirt/FG-IR-21-028
CVEs related to QID 376676
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-028 |
|