PT-2021-6854 · Fortinet · Fortios
Published
2021-05-11
·
Updated
2021-11-18
·
CVE-2021-32600
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 5.6.x
FortiOS versions 6.0.x
FortiOS versions 6.2.0 through 6.2.9
FortiOS versions 6.4.0 through 6.4.6
FortiOS version 7.0.0
Description
The issue is related to insufficient access control in the FortiOS CLI, allowing a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs' information, including the admin account list and the network interface list.
Recommendations
For FortiOS version 7.0.0, update to a version that includes a fix for this issue.
For FortiOS versions 6.4.0 through 6.4.6, update to a version that includes a fix for this issue.
For FortiOS versions 6.2.0 through 6.2.9, update to a version that includes a fix for this issue.
For FortiOS versions 6.0.x, update to a version that includes a fix for this issue.
For FortiOS versions 5.6.x, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the FortiOS CLI to minimize the risk of exploitation.
Fix
Information Disclosure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios