cbcvebase.
CVE-2021-43076
published 2022-09-06

CVE-2021-43076: An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and…

PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.52%
43.0th percentile
An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system files using the shell access.

Affected

8 ranges
VendorProductVersion rangeFixed in
fortinetfortiadc——
fortinetfortiadc——
fortinetfortiadc——
fortinetfortiadc——
fortinetfortiadc5.3.0 – 5.3.7—
fortinetfortiadc5.4.0 – 5.4.5—
fortinetfortiadc6.0.0 – 6.0.4—
fortinetfortiadc6.1.0 – 6.1.5—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.