CVE-2021-22128

HIGH

FortiProxy SSL VPN <2.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-20-235

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (2)
fortinet/fortiproxy 2.0.0
fortinet/fortiproxy < 1.2.9
Published Mar 04, 2021
Tracked Since Feb 18, 2026