CVE-2021-36166

EUVD-2021-22787
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
fortinetfortimail
𝑥
≤ 5.4.12
fortinetfortimail
6.0.0 ≤
𝑥
< 6.0.12
fortinetfortimail
6.2.0 ≤
𝑥
< 6.2.8
fortinetfortimail
6.4.0 ≤
𝑥
< 6.4.6
fortinetfortimail
7.0.0
𝑥
= Vulnerable software versions