CVE Vulnerabilities

CVE-2021-44166

Published: Mar 02, 2022 | Modified: Mar 11, 2022
CVSS 3.x
4.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a users password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.

Affected Software

Name Vendor Start Version End Version
Fortitoken_mobile Fortinet 4.0.0 (including) 4.0.0 (including)
Fortitoken_mobile Fortinet 4.0.1 (including) 4.0.1 (including)
Fortitoken_mobile Fortinet 4.1.1 (including) 4.1.1 (including)
Fortitoken_mobile Fortinet 4.2.1 (including) 4.2.1 (including)
Fortitoken_mobile Fortinet 4.2.2 (including) 4.2.2 (including)
Fortitoken_mobile Fortinet 4.3.0 (including) 4.3.0 (including)
Fortitoken_mobile Fortinet 4.4.0 (including) 4.4.0 (including)
Fortitoken_mobile Fortinet 4.5.0 (including) 4.5.0 (including)
Fortitoken_mobile Fortinet 5.0.2 (including) 5.0.2 (including)
Fortitoken_mobile Fortinet 5.0.3 (including) 5.0.3 (including)
Fortitoken_mobile Fortinet 5.1.0 (including) 5.1.0 (including)

References