Sensitive Information Exposure in FortiManager by Fortinet
CVE-2021-36192
5.2MEDIUM
Summary
The vulnerability in FortiManager allows unauthorized FortiGate users to access sensitive scripts from other ADOMs, potentially compromising security controls and data confidentiality. This exposure poses a risk to the integrity of network operations, enabling unauthorized manipulation or disclosure of sensitive configurations. It is crucial for organizations using affected versions to implement appropriate security measures to mitigate the risk of unauthorized access and to ensure compliance with best practices.
Affected Version(s)
Fortinet FortiManager FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved