CVE Vulnerabilities

CVE-2021-22131

Improper Certificate Validation

Published: Jul 18, 2022 | Modified: Jul 25, 2022
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Fortitoken_mobile Fortinet 0.4.10 (including) 0.4.10 (including)
Fortitoken_mobile Fortinet 0.4.20 (including) 0.4.20 (including)
Fortitoken_mobile Fortinet 3.0.0 (including) 3.0.0 (including)
Fortitoken_mobile Fortinet 3.0.1 (including) 3.0.1 (including)
Fortitoken_mobile Fortinet 3.0.2 (including) 3.0.2 (including)
Fortitoken_mobile Fortinet 3.0.3 (including) 3.0.3 (including)
Fortitoken_mobile Fortinet 3.0.4 (including) 3.0.4 (including)
Fortitoken_mobile Fortinet 3.0.5 (including) 3.0.5 (including)
Fortitoken_mobile Fortinet 4.0.0 (including) 4.0.0 (including)
Fortitoken_mobile Fortinet 4.0.1 (including) 4.0.1 (including)
Fortitoken_mobile Fortinet 4.0.3 (including) 4.0.3 (including)
Fortitoken_mobile Fortinet 4.1.0 (including) 4.1.0 (including)
Fortitoken_mobile Fortinet 4.1.1 (including) 4.1.1 (including)
Fortitoken_mobile Fortinet 4.2.0 (including) 4.2.0 (including)
Fortitoken_mobile Fortinet 4.2.1 (including) 4.2.1 (including)
Fortitoken_mobile Fortinet 4.2.2 (including) 4.2.2 (including)
Fortitoken_mobile Fortinet 4.3.0 (including) 4.3.0 (including)
Fortitoken_mobile Fortinet 4.4.0 (including) 4.4.0 (including)
Fortitoken_mobile Fortinet 4.5.0 (including) 4.5.0 (including)
Fortitoken_mobile Fortinet 5.0.2 (including) 5.0.2 (including)
Fortitoken_mobile Fortinet 5.0.3 (including) 5.0.3 (including)
Fortitoken_mobile Fortinet 5.2.0 (including) 5.2.0 (including)

Potential Mitigations

References