CVE Vulnerabilities

CVE-2021-32587

Published: Aug 06, 2021 | Modified: Jun 28, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 5.6.0 (including) 6.4.6 (excluding)
Fortianalyzer Fortinet 7.0.0 (including) 7.0.1 (excluding)
Fortimanager Fortinet 5.6.0 (including) 6.4.6 (excluding)
Fortimanager Fortinet 7.0.0 (including) 7.0.1 (excluding)

References