CVE-2021-43065

HIGH

Fortinet FortiNAC <9.2.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-21-178

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 33.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (2)
fortinet/fortinac 9.2.0
fortinet/fortinac 8.8.0 - 8.8.10
Published Dec 09, 2021
Tracked Since Feb 18, 2026