CVE-2021-32600 MEDIUM

CVE-2021-32600

Vendor Fortinet
Product Fortinet FortiOS
Published November 17, 2021
Last update October 25, 2024

CVSS base score

5.0/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:F/RL:X/RC:X

What the vulnerability does

01Description

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.

Key dates

02Disclosure timeline

November 17, 2021 CVE published
October 25, 2024 Record updated