PT-2021-7555 · Fortinet · Fortinac
Published
2021-12-07
·
Updated
2022-07-12
·
CVE-2021-41021
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiNAC versions 8.8.8 and below
FortiNAC versions 9.1.2 and below
Description
The issue is related to insufficient access control in Fortinet FortiNAC, allowing an attacker to escalate privileges to the root level using the
sudo command. This can be exploited by an admin user.Recommendations
For FortiNAC versions 8.8.8 and below, consider restricting the use of the
sudo command until a patch is available.
For FortiNAC versions 9.1.2 and below, consider restricting the use of the sudo command until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortinac