7.8

CVE-2021-26110

An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.

Data is provided by the National Vulnerability Database (NVD)
FortinetFortiproxy Version >= 1.0.0 <= 1.0.7
FortinetFortiproxy Version >= 1.1.0 <= 1.1.6
FortinetFortiproxy Version >= 1.2.0 <= 1.2.9
FortinetFortiproxy Version2.0.0
FortinetFortiproxy Version2.0.1
FortinetFortios Version >= 5.6.0 <= 5.6.14
FortinetFortios Version >= 6.0.0 <= 6.0.12
FortinetFortios Version >= 6.2.0 <= 6.2.9
FortinetFortios Version >= 6.4.0 <= 6.4.6
FortinetFortios Version7.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.094
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@fortinet.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H