High severity7.5NVD Advisory· Published Aug 4, 2021· Updated Jun 17, 2026
CVE-2021-22124
CVE-2021-22124
Description
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
Affected products
5cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*range: >=4.0.0,<=4.3.4
- (no CPE)range: <6.0.6
- (no CPE)range: FortiSandbox 3.2.2, 3.2.1, 3.2.0, 3.1.4, 3.1.3, 3.1.2, 3.1.1, 3.1.0, 3.0.6, 3.0.5, 3.0.4, 3.0.3, 3.0.2, 3.0.1, 3.0.0, FortiAuthenticator before 6.0.6
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: >=3.0.0,<3.0.7
- (no CPE)range: 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-170nvdVendor Advisory
News mentions
0No linked articles in our index yet.