Learn about CVE-2021-43067 impacting Fortinet FortiAuthenticator. Attackers can duplicate a target LDAP user's token. Find mitigation steps here.
Fortinet FortiAuthenticator versions 6.4.0, 6.3.2, and below are vulnerable to exposure of sensitive information leading to unauthorized access.
Understanding CVE-2021-43067
A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator versions allows attackers to duplicate a target LDAP user's 2-factor authentication token.
What is CVE-2021-43067?
The Impact of CVE-2021-43067
Technical Details of CVE-2021-43067
FortiAuthenticator vulnerability details
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting against CVE-2021-43067
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates