516
VMScore

CVE-2021-26088

Published: 12/07/2021 Updated: 02/08/2021
CVSS v2 Base Score: 5.8 | Impact Score: 6.4 | Exploitability Score: 6.5
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortinet single sign-on

Github Repositories

PoC for CVE-2021-26088 written in PowerShell

PoC for CVE-2021-26088 written in PowerShell Description An improper authentication vulnerability in FSSO Collector may allow an unauthenticated user to bypass any firewall authentication rule and access the protected network via sending specifically crafted UDP login notification packets wwwfortiguardcom/psirt/FG-IR-20-191 Content forge_authps1: main exploit che