Vulnerability Description
The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiportal | <= 4.0.4 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-21-099Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-21-099Vendor Advisory
FAQ
What is CVE-2021-36171?
CVE-2021-36171 is a vulnerability with a CVSS score of 8.1 (HIGH). The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whol...
How severe is CVE-2021-36171?
CVE-2021-36171 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36171?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiportal.