QID 379375

Date Published: 2024-03-20

QID 379375: FortiAuthenticator Improper access control in HA service (FG-IR-20-217)

CVE-2021-36177:An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.

Affected Products:

FortiAuthenticator 6.3.2 and below.
P>QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiAuthenticator by executing command "get system status".

,P>Successful exploitation of this vulnerability may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-20-217

    Vendor References

    CVEs related to QID 379375

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-20-217 URL Logo www.fortiguard.com/psirt/FG-IR-20-217