Vulnerability Description
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortitoken Mobile | 0.4.10 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/advisory/FG-IR-21-024PatchVendor Advisory
- https://fortiguard.com/advisory/FG-IR-21-024PatchVendor Advisory
FAQ
What is CVE-2021-22131?
CVE-2021-22131 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 a...
How severe is CVE-2021-22131?
CVE-2021-22131 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22131?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortitoken Mobile.