CVE-2021-32587
published 2021-08-06CVE-2021-32587: An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.65%
46.7th percentile
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 5.6.0 < 6.4.6 | 6.4.6 |
| fortinet | fortianalyzer | >= 7.0.0 < 7.0.1 | 7.0.1 |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 5.6.0 < 6.4.6 | 6.4.6 |
| fortinet | fortimanager | >= 7.0.0 < 7.0.1 | 7.0.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9662-jc44-mgqr: An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7
ghsa_unreviewed·2022-05-24
CVE-2021-32587 [MEDIUM] CWE-863 GHSA-9662-jc44-mgqr: An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11and below, 5.6.11and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
Fortinet
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 a...
vendor_fortinet·2021-08-06·CVSS 4.3
CVE-2021-32587 [MEDIUM] An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 a...
FG-IR-21-059: An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 a...
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
CVEs: CVE-2021-32587
CVSS: 4.3 (medium)
Affected products: FortiAnalyzer, FortiManager
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-06
Published