4.3
CVE-2021-32587
- EPSS 0.2%
- Veröffentlicht 06.08.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:19
- Quelle psirt@fortinet.com
- Teams Watchlist Login
- Unerledigt Login
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortianalyzer Version >= 5.6.0 < 6.4.6
Fortinet ≫ Fortianalyzer Version >= 7.0.0 < 7.0.1
Fortinet ≫ Fortimanager Version >= 5.6.0 < 6.4.6
Fortinet ≫ Fortimanager Version >= 7.0.0 < 7.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.2% | 0.396 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
psirt@fortinet.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|