<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Missing digital certificate validation</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-21-024</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2022-06-07T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2022-06-07T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2022-06-07T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper validation of certificate with host mismatch vulnerability [CWE-297] in FortiTokenMobile may allow an unauthenticated user to spoof the validation server identity and achieve a Man-in-the-Middle attack.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Information disclosure
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiTokenIOS 5.4 all versions are not affectedFortiTokenIOS 5.3 all versions are not affectedFortiTokenIOS 5.2 all versionsFortiTokenIOS 5.1 all versions are not affectedFortiTokenIOS 5.0 all versions are not affectedFortiTokenIOS 4.6 all versions are not affectedFortiTokenIOS 4.3 all versionsFortiTokenIOS 4.2 all versionsFortiTokenIOS 4.1 all versionsFortiTokenIOS 3.0 all versionsFortiTokenAndroid 5.2 all versions are not affectedFortiTokenAndroid 5.1 all versions are not affectedFortiTokenAndroid 5.0 all versionsFortiTokenAndroid 4.5 all versionsFortiTokenAndroid 4.4 all versionsFortiTokenAndroid 4.3 all versionsFortiTokenAndroid 4.2 all versionsFortiTokenAndroid 4.1 all versionsFortiTokenAndroid 4.0 all versionsFortiTokenAndroid 3.0 all versionsFortiTokenAndroid 0.4 all versionsFortiTokenMobileWP 4.1 all versions are not affectedFortiTokenMobileWP 4.0 all versionsFortiTokenMobileWP 3.0 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Upgrade FortiTokenMobile for Android to version 5.1.0 or aboveUpgrade FortiTokenMobile for iOS to version 5.3.0 or aboveUpgrade FortiTokenMobile for Windows to version 4.1.0 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiTokenAndroid" Type="Product Name">
                <Branch Name="5.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-5.0.3">FortiTokenAndroid 5.0.3</FullProductName>
                </Branch>
                <Branch Name="5.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-5.0.2">FortiTokenAndroid 5.0.2</FullProductName>
                </Branch>
                <Branch Name="4.5.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.5.0">FortiTokenAndroid 4.5.0</FullProductName>
                </Branch>
                <Branch Name="4.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.4.0">FortiTokenAndroid 4.4.0</FullProductName>
                </Branch>
                <Branch Name="4.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.3.0">FortiTokenAndroid 4.3.0</FullProductName>
                </Branch>
                <Branch Name="4.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.2.2">FortiTokenAndroid 4.2.2</FullProductName>
                </Branch>
                <Branch Name="4.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.2.1">FortiTokenAndroid 4.2.1</FullProductName>
                </Branch>
                <Branch Name="4.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.1.1">FortiTokenAndroid 4.1.1</FullProductName>
                </Branch>
                <Branch Name="4.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.0.1">FortiTokenAndroid 4.0.1</FullProductName>
                </Branch>
                <Branch Name="4.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-4.0.0">FortiTokenAndroid 4.0.0</FullProductName>
                </Branch>
                <Branch Name="3.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-3.0.4">FortiTokenAndroid 3.0.4</FullProductName>
                </Branch>
                <Branch Name="3.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-3.0.3">FortiTokenAndroid 3.0.3</FullProductName>
                </Branch>
                <Branch Name="3.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-3.0.2">FortiTokenAndroid 3.0.2</FullProductName>
                </Branch>
                <Branch Name="3.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-3.0.1">FortiTokenAndroid 3.0.1</FullProductName>
                </Branch>
                <Branch Name="3.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-3.0.0">FortiTokenAndroid 3.0.0</FullProductName>
                </Branch>
                <Branch Name="0.4.20" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-0.4.20">FortiTokenAndroid 0.4.20</FullProductName>
                </Branch>
                <Branch Name="0.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiTokenAndroid-0.4.10">FortiTokenAndroid 0.4.10</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiTokenIOS" Type="Product Name">
                <Branch Name="5.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-5.2.0">FortiTokenIOS 5.2.0</FullProductName>
                </Branch>
                <Branch Name="4.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-4.3.0">FortiTokenIOS 4.3.0</FullProductName>
                </Branch>
                <Branch Name="4.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-4.2.0">FortiTokenIOS 4.2.0</FullProductName>
                </Branch>
                <Branch Name="4.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-4.1.1">FortiTokenIOS 4.1.1</FullProductName>
                </Branch>
                <Branch Name="4.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-4.1.0">FortiTokenIOS 4.1.0</FullProductName>
                </Branch>
                <Branch Name="3.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-3.0.5">FortiTokenIOS 3.0.5</FullProductName>
                </Branch>
                <Branch Name="3.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-3.0.4">FortiTokenIOS 3.0.4</FullProductName>
                </Branch>
                <Branch Name="3.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-3.0.3">FortiTokenIOS 3.0.3</FullProductName>
                </Branch>
                <Branch Name="3.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-3.0.2">FortiTokenIOS 3.0.2</FullProductName>
                </Branch>
                <Branch Name="3.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiTokenIOS-3.0.1">FortiTokenIOS 3.0.1</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiTokenMobileWP" Type="Product Name">
                <Branch Name="4.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiTokenMobileWP-4.0.3">FortiTokenMobileWP 4.0.3</FullProductName>
                </Branch>
                <Branch Name="3.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiTokenMobileWP-3.0.1">FortiTokenMobileWP 3.0.1</FullProductName>
                </Branch>
                <Branch Name="3.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiTokenMobileWP-3.0.0">FortiTokenMobileWP 3.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Missing digital certificate validation</Title>
        <cvrf:CVE>CVE-2021-22131</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiTokenAndroid-5.0.3</ProductID>
                <ProductID>FortiTokenAndroid-5.0.2</ProductID>
                <ProductID>FortiTokenAndroid-4.5.0</ProductID>
                <ProductID>FortiTokenAndroid-4.4.0</ProductID>
                <ProductID>FortiTokenAndroid-4.3.0</ProductID>
                <ProductID>FortiTokenAndroid-4.2.2</ProductID>
                <ProductID>FortiTokenAndroid-4.2.1</ProductID>
                <ProductID>FortiTokenAndroid-4.1.1</ProductID>
                <ProductID>FortiTokenAndroid-4.0.1</ProductID>
                <ProductID>FortiTokenAndroid-4.0.0</ProductID>
                <ProductID>FortiTokenAndroid-3.0.4</ProductID>
                <ProductID>FortiTokenAndroid-3.0.3</ProductID>
                <ProductID>FortiTokenAndroid-3.0.2</ProductID>
                <ProductID>FortiTokenAndroid-3.0.1</ProductID>
                <ProductID>FortiTokenAndroid-3.0.0</ProductID>
                <ProductID>FortiTokenAndroid-0.4.20</ProductID>
                <ProductID>FortiTokenAndroid-0.4.10</ProductID>
                <ProductID>FortiTokenIOS-5.2.0</ProductID>
                <ProductID>FortiTokenIOS-4.3.0</ProductID>
                <ProductID>FortiTokenIOS-4.2.0</ProductID>
                <ProductID>FortiTokenIOS-4.1.1</ProductID>
                <ProductID>FortiTokenIOS-4.1.0</ProductID>
                <ProductID>FortiTokenIOS-3.0.5</ProductID>
                <ProductID>FortiTokenIOS-3.0.4</ProductID>
                <ProductID>FortiTokenIOS-3.0.3</ProductID>
                <ProductID>FortiTokenIOS-3.0.2</ProductID>
                <ProductID>FortiTokenIOS-3.0.1</ProductID>
                <ProductID>FortiTokenMobileWP-4.0.3</ProductID>
                <ProductID>FortiTokenMobileWP-3.0.1</ProductID>
                <ProductID>FortiTokenMobileWP-3.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.1</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H/E:P/RL:X/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-21-024</URL>
                <Description>Missing digital certificate validation</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>