CVE-2021-36171
01.03.2022, 18:15
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.
Vendor | Product | Version |
---|---|---|
fortinet | fortiportal | 𝑥 ≤ 4.0.4 |
fortinet | fortiportal | 4.1.0 ≤ 𝑥 ≤ 4.1.2 |
fortinet | fortiportal | 4.2.0 ≤ 𝑥 ≤ 4.2.4 |
fortinet | fortiportal | 5.0.0 ≤ 𝑥 ≤ 5.0.3 |
fortinet | fortiportal | 5.1.0 ≤ 𝑥 ≤ 5.1.2 |
fortinet | fortiportal | 5.2.0 ≤ 𝑥 < 5.2.7 |
fortinet | fortiportal | 5.3.0 ≤ 𝑥 < 5.3.7 |
fortinet | fortiportal | 6.0.0 ≤ 𝑥 < 6.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration