ZeroHour

CVE-2021-36170

CVSS 3.1
3.2 low
EPSS
<1%p13
Published
()
Modified
Description

An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext.

Vendors
fortinet
Products
fortianalyzer, fortimanager
Weakness
CWE-522
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.