7.8

CVE-2021-26110

An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiProxy Version >= 1.0.0 <= 1.0.7
Fortinet ≫ FortiProxy Version >= 1.1.0 <= 1.1.6
Fortinet ≫ FortiProxy Version >= 1.2.0 <= 1.2.9
Fortinet ≫ FortiProxy Version 2.0.0
Fortinet ≫ FortiProxy Version 2.0.1
Fortinet ≫ FortiOS Version >= 5.6.0 <= 5.6.14
Fortinet ≫ FortiOS Version >= 6.0.0 <= 6.0.12
Fortinet ≫ FortiOS Version >= 6.2.0 <= 6.2.9
Fortinet ≫ FortiOS Version >= 6.4.0 <= 6.4.6
Fortinet ≫ FortiOS Version 7.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.157
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Fortinet 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://fortiguard.com/advisory/FG-IR-20-131
Vendor Advisory