CVE-2021-36166

An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
fortinetfortimail
𝑥
≤ 5.4.12
fortinetfortimail
6.0.0 ≤
𝑥
< 6.0.12
fortinetfortimail
6.2.0 ≤
𝑥
< 6.2.8
fortinetfortimail
6.4.0 ≤
𝑥
< 6.4.6
fortinetfortimail
7.0.0
𝑥
= Vulnerable software versions