Improper Access Control in Fortinet's FortiWLC Product
CVE-2021-32584

4.8MEDIUM

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
17 March 2025

Summary

An improper access control vulnerability in Fortinet's FortiWLC can be exploited by unauthenticated remote attackers. By entering a specific URL, attackers may gain unauthorized access to limited CGI resources within the web management interface. This flaw exposes sensitive configuration details, potentially compromising the security posture of the affected systems.

Affected Version(s)

FortiWLC 8.6.0

FortiWLC 8.5.0 <= 8.5.3

FortiWLC 8.4.4 <= 8.4.8

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.