Medium severity4.2NVD Advisory· Published Feb 2, 2022· Updated Jun 17, 2026
CVE-2021-36177
CVE-2021-36177
Description
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
Affected products
3cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*range: >=6.0.0,<6.3.3
- (no CPE)
- (no CPE)range: <=6.3.2, 6.2.x, 6.1.x, 6.0.x
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-20-217nvdVendor Advisory
News mentions
0No linked articles in our index yet.