← back
CVE-2021-32584

CVE-2021-32584

CVSS 4.8 MEDIUMEPSS 0.6%CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
17 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functionality by just specifying the correct URL. The vulnerability applies only to limited CGI resources and might allow the unauthorized party to access configuration details.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Affected products
Fortinet · FortiWLC

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →