CVE-2021-24017

MEDIUM

FortiManager < 6.2.7 - Improper Authentication via Request Handler

Title source: llm
STIX 2.1

Description

An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-20-189

Scores

CVSS v3 5.4
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
fortinet/fortimanager < 6.2.7
Published Sep 30, 2021
Tracked Since Feb 18, 2026