SB2021111604 - Information disclosure in Fortinet FortiOS
Published: November 16, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper validation of certificate with host mismatch (CVE-ID: CVE-2021-41019)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper certificate validation with host mismatch when connecting to an LDAP server under attacker's control via options in GUI. A remote attacker can obtain AD credentials.
Remediation
Install update from vendor's website.