CVE-2021-32600
published 2021-11-17CVE-2021-32600: An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may…
PriorityP412low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
EPSS
0.57%
43.6th percentile
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 5.6.0 – 5.6.9 | — |
| fortinet | fortios | 6.0.0 – 6.0.13 | — |
| fortinet | fortios | >= 6.2.0 < 6.2.10 | 6.2.10 |
| fortinet | fortios | >= 6.4.0 < 6.4.7 | 6.4.7 |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vcfg-hrf9-fp2h: An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7
ghsa_unreviewed·2022-05-24
CVE-2021-32600 [LOW] GHSA-vcfg-hrf9-fp2h: An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.
Fortinet
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6...
vendor_fortinet·2021-11-17·CVSS 5.0
CVE-2021-32600 [MEDIUM] CWE-200 An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6...
FG-IR-20-243: An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6...
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.
CVEs: CVE-2021-32600
CWEs: CWE-200
CVSS: 5.0 (medium)
Affected products: FortiOS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-17
Published