Improper Access Control in FortiOS and FortiProxy Products
CVE-2021-26110
7.8HIGH
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 8 December 2021
Summary
An improper access control vulnerability exists in FortiOS autod daemon and FortiProxy products, which may permit a low-privileged authenticated attacker to escalate privileges to super_admin. This can occur through a specifically crafted configuration of fabric automation CLI scripts and auto-script features, potentially compromising device integrity and security. Users are encouraged to review their configurations and apply the necessary patches to mitigate this risk.
Affected Version(s)
Fortinet FortiOS, FortiProxy FortiOS 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below. FortiProxy 2.0.1 and below, 1.2.9 and below
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved