CVE-2021-24017
—CVSS 3.1
4.3 medium
EPSS
<1%p44
Published
()
Modified
Description
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
- Vendors
- fortinet
- Products
- fortimanager
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.