CVE-2021-36192

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
03/11/2021
Last modified:
03/05/2022

Description

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 5.6.0 (including) 5.6.11 (including)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.11 (including)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.8 (including)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.6 (excluding)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.1 (excluding)


References to Advisories, Solutions, and Tools