CVE-2021-42758

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/12/2021
Last modified:
10/12/2021

Description

An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiwlc:*:*:*:*:*:*:*:* 8.2.4 (including) 8.2.7 (including)
cpe:2.3:a:fortinet:fortiwlc:*:*:*:*:*:*:*:* 8.3.0 (including) 8.3.3 (including)
cpe:2.3:a:fortinet:fortiwlc:*:*:*:*:*:*:*:* 8.5.0 (including) 8.5.5 (including)
cpe:2.3:a:fortinet:fortiwlc:8.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.1.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.1.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiwlc:8.4.8:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools