Improper Access Control in FortiOS and FortiProxy Products
CVE-2021-26110

7.8HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
8 December 2021

Summary

An improper access control vulnerability exists in FortiOS autod daemon and FortiProxy products, which may permit a low-privileged authenticated attacker to escalate privileges to super_admin. This can occur through a specifically crafted configuration of fabric automation CLI scripts and auto-script features, potentially compromising device integrity and security. Users are encouraged to review their configurations and apply the necessary patches to mitigate this risk.

Affected Version(s)

Fortinet FortiOS, FortiProxy FortiOS 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below. FortiProxy 2.0.1 and below, 1.2.9 and below

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.