← Vulnerability feed

Vulnerability record · CVE-2021-22124 · published 4 August 2021

CVE-2021-22124: Fortinet fortiauthenticator uncontrolled resource consumption vulnerability

Fortinet · Fortiauthenticator

An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.

7.5 CVSS 3.1 High EPSS 1.0% · top 38.0% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score, v2 7.8
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22124 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-25089Fortinet FortiSandbox unauthenticated OS command injectionFortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to neutralize special elements in HTTP request handling, allowing OS command injection (C…KEVEPSS 76%analysed9.8CVE-2026-39808Fortinet FortiSandbox OS command injectionFortiSandbox 4.4.0 through 4.4.8 fails to neutralize special elements used in OS commands, allowing command injection. The flaw is remotely reachable…KEVEPSS 47%analysed9.8CVE-2026-44277Fortinet fortiauthenticator improper access control vulnerabilityA improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, Forti…EPSS 0.48%9.8CVE-2026-26083Fortinet fortisandbox missing authorization vulnerabilityA missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…EPSS 0.50%9.8CVE-2026-39813Fortinet fortisandbox vulnerabilityA path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…EPSS 0.72%9.6CVE-2025-52436Fortinet fortisandbox cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…EPSS 6.5%9.0CVE-2024-27781Fortinet fortisandbox cross-site scripting vulnerabilityAn improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, F…EPSS 28%9.0CVE-2013-6990Fortinet fortiauthenticator permissions and access controls vulnerabilityFortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2021-22124), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.