PT-2021-7569 · Fortinet · Fortimanager

Published

2021-08-03

·

Updated

2021-09-10

·

CVE-2021-24006

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiManager versions 6.4.0 through 6.4.3
Description The issue is related to improper access control in FortiManager, which may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel by directly visiting its URL. This could potentially allow a remote attacker to disclose protected information.
Recommendations For FortiManager versions 6.4.0 through 6.4.3, consider restricting access to the SD-WAN Orchestrator panel until a patch is available. As a temporary workaround, limit the ability of restricted user profiles to directly visit the SD-WAN Orchestrator panel's URL.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00092
CVE-2021-24006

Affected Products

Fortimanager