CVE-2021-22131

MEDIUM

FortiToken Mobile <= 5.0.3 (Android), <= 5.2.0 (iOS), <= 4.0.3 (Windows) - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via man-in-the-middle attacks.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-21-024

Scores

CVSS v3 6.4
EPSS 0.0005
EPSS Percentile 16.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (22)
fortinet/fortitoken_mobile 0.4.10
fortinet/fortitoken_mobile 0.4.20
fortinet/fortitoken_mobile 3.0.0 (2 CPE variants)
fortinet/fortitoken_mobile 3.0.1 (3 CPE variants)
fortinet/fortitoken_mobile 3.0.2 (2 CPE variants)
fortinet/fortitoken_mobile 3.0.3 (2 CPE variants)
fortinet/fortitoken_mobile 3.0.4 (2 CPE variants)
fortinet/fortitoken_mobile 3.0.5
fortinet/fortitoken_mobile 4.0.0
fortinet/fortitoken_mobile 4.0.1
... and 12 more
Published Jul 18, 2022
Tracked Since Feb 18, 2026