CVE-2021-24017
CVE-2021-24017
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 Sep 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:H/RL:X/RC:X
Affected products
Fortinet · Fortinet FortiManagerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →