CVE Vulnerabilities

CVE-2021-41032

Published: May 04, 2022 | Modified: Jul 12, 2022
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs using specific CLI commands.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.2.0 (including) 6.4.9 (excluding)
Fortios Fortinet 7.0.0 (including) 7.0.4 (excluding)

References