CVE-2021-32600

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
17/11/2021
Last modified:
28/06/2022

Description

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 5.6.0 (including) 5.6.9 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.13 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.10 (excluding)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.7 (excluding)
cpe:2.3:o:fortinet:fortios:7.0.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools