CVE-2021-43076

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
06/09/2022
Last modified:
13/09/2022

Description

An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system files using the shell access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.7 (including)
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.5 (including)
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.4 (including)
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:* 6.1.0 (including) 6.1.5 (including)
cpe:2.3:a:fortinet:fortiadc:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:6.2.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools