Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiAuthenticator 安全漏洞
Vulnerability Description
Fortinet FortiAuthenticator是美国飞塔(Fortinet)公司的一款集中式的用户身份管理解决方案。 Fortinet FortiAuthenticator HA service 6.3.2及之前6.3.x版本,6.2.x版本,6.1.x版本,6.0.x版本存在安全漏洞,该漏洞允许与HA管理接口在同一vlan的攻击者利用该漏洞进行未经认证的直接连接到FAC的数据库。
CVSS Information
N/A
Vulnerability Type
N/A