CVE-2021-36171

EUVD-2021-22792
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
fortinetfortiportal
𝑥
≤ 4.0.4
fortinetfortiportal
4.1.0 ≤
𝑥
≤ 4.1.2
fortinetfortiportal
4.2.0 ≤
𝑥
≤ 4.2.4
fortinetfortiportal
5.0.0 ≤
𝑥
≤ 5.0.3
fortinetfortiportal
5.1.0 ≤
𝑥
≤ 5.1.2
fortinetfortiportal
5.2.0 ≤
𝑥
< 5.2.7
fortinetfortiportal
5.3.0 ≤
𝑥
< 5.3.7
fortinetfortiportal
6.0.0 ≤
𝑥
< 6.0.6
𝑥
= Vulnerable software versions