Vulnerability Database

308,485

Total vulnerabilities in the database

CVE-2021-22128

An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.

  • Published: Mar 4, 2021
  • Updated: Nov 16, 2025
  • CVE: CVE-2021-22128
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.1
  • AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

CVSS v2:

  • Severity: Low
  • Score: 4
  • AV:N/AC:L/Au:S/C:P/I:N/A:N

No CWE or OWASP classifications available.