FortiMail - Administrative authentication bypass
Fortinet PSIRT Advisories
Fortinet PSIRT Contact:
Website: https://fortiguard.fortinet.com/faq/psirt-contact
FG-IR-21-028
Final
1
1
2022-03-01T00:00:00
Current version
2022-03-01T00:00:00
2022-03-01T00:00:00
An improper authentication vulnerability [CWE-287] in FortiMail may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
None
Improper access control
FortiMail version 7.0.0 and below.FortiMail version 6.4.5 and below.FortiMail version 6.2.7 and below.FortiMail version 6.0.11 and below.FortiMail version 5.4.12 and below.
Upgrade to FortiMail version 7.0.1.Upgrade to FortiMail version 6.4.6.Upgrade to FortiMail version 6.2.8.Upgrade to FortiMail version 6.0.12.
Discovered and reported by Giuseppe Cocomazzi of Fortinet Product Security team.
FortiMail 7.0.0
FortiMail 6.4.5
FortiMail 6.4.4
FortiMail 6.4.3
FortiMail 6.4.2
FortiMail 6.4.1
FortiMail 6.4.0
FortiMail 6.2.7
FortiMail 6.2.6
FortiMail 6.2.5
FortiMail 6.2.4
FortiMail 6.2.3
FortiMail 6.2.2
FortiMail 6.2.1
FortiMail 6.2.0
FortiMail 6.0.11
FortiMail 6.0.10
FortiMail 6.0.9
FortiMail 6.0.8
FortiMail 6.0.7
FortiMail 6.0.6
FortiMail 6.0.5
FortiMail 6.0.4
FortiMail 6.0.3
FortiMail 6.0.2
FortiMail 6.0.1
FortiMail 6.0.0
FortiMail 5.4.12
FortiMail 5.4.11
FortiMail 5.4.10
FortiMail 5.4.9
FortiMail 5.4.8
FortiMail 5.4.7
FortiMail 5.4.6
FortiMail 5.4.5
FortiMail 5.4.4
FortiMail 5.4.3
FortiMail 5.4.2
FortiMail 5.4.1
FortiMail 5.4.0
FortiMail - Administrative authentication bypass
CVE-2021-36166
FortiMail-7.0.0
FortiMail-6.4.5
FortiMail-6.4.4
FortiMail-6.4.3
FortiMail-6.4.2
FortiMail-6.4.1
FortiMail-6.4.0
FortiMail-6.2.7
FortiMail-6.2.6
FortiMail-6.2.5
FortiMail-6.2.4
FortiMail-6.2.3
FortiMail-6.2.2
FortiMail-6.2.1
FortiMail-6.2.0
FortiMail-6.0.11
FortiMail-6.0.10
FortiMail-6.0.9
FortiMail-6.0.8
FortiMail-6.0.7
FortiMail-6.0.6
FortiMail-6.0.5
FortiMail-6.0.4
FortiMail-6.0.3
FortiMail-6.0.2
FortiMail-6.0.1
FortiMail-6.0.0
FortiMail-5.4.12
FortiMail-5.4.11
FortiMail-5.4.10
FortiMail-5.4.9
FortiMail-5.4.8
FortiMail-5.4.7
FortiMail-5.4.6
FortiMail-5.4.5
FortiMail-5.4.4
FortiMail-5.4.3
FortiMail-5.4.2
FortiMail-5.4.1
FortiMail-5.4.0
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
https://fortiguard.fortinet.com/psirt/FG-IR-21-028
FortiMail - Administrative authentication bypass
Reference>