CVE-2021-26088
 
Severity Score
9.6
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.
Una vulnerabilidad de autenticación inapropiada en FSSO Collector versiones 5.0.295 de y posteriores, puede permitir a un usuario no autenticado omitir una política de firewall de FSSO y acceder a la red protegida por medio del envío de paquetes de notificación de inicio de sesión UDP específicamente diseñados
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-01-25 CVE Reserved
- 2021-07-12 CVE Published
- 2023-05-09 First Exploit
- 2024-03-27 EPSS Updated
- 2024-10-25 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/theogobinet/CVE-2021-26088 | 2023-05-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/advisory/FG-IR-20-191 | 2021-08-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortinet Single Sign-on Search vendor "Fortinet" for product "Fortinet Single Sign-on" | < 6.4.6 Search vendor "Fortinet" for product "Fortinet Single Sign-on" and version " < 6.4.6" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortinet Single Sign-on Search vendor "Fortinet" for product "Fortinet Single Sign-on" | >= 7.0.0 < 7.0.1 Search vendor "Fortinet" for product "Fortinet Single Sign-on" and version " >= 7.0.0 < 7.0.1" | - |
Affected
|