CVE-2021-36166

An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
fortinetfortimail
𝑥
≤ 5.4.12
fortinetfortimail
6.0.0 ≤
𝑥
< 6.0.12
fortinetfortimail
6.2.0 ≤
𝑥
< 6.2.8
fortinetfortimail
6.4.0 ≤
𝑥
< 6.4.6
fortinetfortimail
7.0.0
𝑥
= Vulnerable software versions