Description
An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31016 | An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-21-210 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T21:00:22.919Z
Reserved: 2021-11-23T00:00:00.000Z
Link: CVE-2021-44166
Updated: 2024-08-04T04:17:24.370Z
Status : Modified
Published: 2022-03-02T10:15:07.750
Modified: 2024-11-21T06:30:29.077
Link: CVE-2021-44166
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD