PT-2021-7555 · Fortinet · Fortinac

Published

2021-12-07

·

Updated

2022-07-12

·

CVE-2021-41021

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiNAC versions 8.8.8 and below FortiNAC versions 9.1.2 and below
Description The issue is related to insufficient access control in Fortinet FortiNAC, allowing an attacker to escalate privileges to the root level using the sudo command. This can be exploited by an admin user.
Recommendations For FortiNAC versions 8.8.8 and below, consider restricting the use of the sudo command until a patch is available. For FortiNAC versions 9.1.2 and below, consider restricting the use of the sudo command until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00003
CVE-2021-41021

Affected Products

Fortinac