Exploitation Summary
EIP tracks 2 public exploits for CVE-2021-24006. PoCs published by chessredoffsec.
AI-analyzed exploit summary The repository contains a functional Python script that exploits CVE-2021-24006, an improper access control vulnerability in FortiManager. The exploit demonstrates how a restricted admin user can bypass access controls to access the SD-WAN Orchestrator interface.
Description
An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
Exploits (2)
The repository contains a functional Python script that exploits CVE-2021-24006, an improper access control vulnerability in FortiManager. The exploit demonstrates how a restricted admin user can bypass access controls to access the SD-WAN Orchestrator interface.
This repository contains a functional Python exploit for CVE-2021-24006, an improper access control vulnerability in FortiManager. The exploit demonstrates how a restricted admin user can bypass access controls to access the SD-WAN Orchestrator interface.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L