Sensitive Information Exposure in FortiManager by Fortinet
CVE-2021-36192

5.2MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
3 November 2021

Summary

The vulnerability in FortiManager allows unauthorized FortiGate users to access sensitive scripts from other ADOMs, potentially compromising security controls and data confidentiality. This exposure poses a risk to the integrity of network operations, enabling unauthorized manipulation or disclosure of sensitive configurations. It is crucial for organizations using affected versions to implement appropriate security measures to mitigate the risk of unauthorized access and to ensure compliance with best practices.

Affected Version(s)

Fortinet FortiManager FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.