ZeroHour

CVE-2021-24017

CVSS 3.1
4.3 medium
EPSS
<1%p44
Published
()
Modified
Description

An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.

Vendors
fortinet
Products
fortimanager
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.