CVE-2021-22124
04.08.2021, 19:15
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortiauthenticator | 4.0.0 ≤ 𝑥 ≤ 4.3.4 |
fortinet | fortiauthenticator | 5.0.0 ≤ 𝑥 ≤ 5.5.0 |
fortinet | fortiauthenticator | 6.0.0 ≤ 𝑥 < 6.0.6 |
fortinet | fortisandbox | 3.0.0 ≤ 𝑥 < 3.0.7 |
fortinet | fortisandbox | 3.1.0 ≤ 𝑥 < 3.1.5 |
fortinet | fortisandbox | 3.2.0 ≤ 𝑥 < 3.2.2 |
𝑥
= Vulnerable software versions