Lucene search

K
cveFortinetCVE-2021-26110
HistoryDec 08, 2021 - 11:15 a.m.

CVE-2021-26110

2021-12-0811:15:11
fortinet
web.nvd.nist.gov
21
6
cve-2021-26110
improper access control
fortios
autod daemon
fortiproxy
privilege escalation
cwe-284
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%

An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.

Affected configurations

Nvd
Node
fortinetfortiproxyRange1.0.0–1.0.7
OR
fortinetfortiproxyRange1.1.0–1.1.6
OR
fortinetfortiproxyRange1.2.0–1.2.9
OR
fortinetfortiproxyMatch2.0.0
OR
fortinetfortiproxyMatch2.0.1
OR
fortinetfortiosRange5.6.0–5.6.14
OR
fortinetfortiosRange6.0.0–6.0.12
OR
fortinetfortiosRange6.2.0–6.2.9
OR
fortinetfortiosRange6.4.0–6.4.6
OR
fortinetfortiosMatch7.0.0
VendorProductVersionCPE
fortinetfortiproxy*cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
fortinetfortiproxy2.0.0cpe:2.3:a:fortinet:fortiproxy:2.0.0:*:*:*:*:*:*:*
fortinetfortiproxy2.0.1cpe:2.3:a:fortinet:fortiproxy:2.0.1:*:*:*:*:*:*:*
fortinetfortios*cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
fortinetfortios7.0.0cpe:2.3:o:fortinet:fortios:7.0.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Fortinet FortiOS, FortiProxy",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiOS 7.0.0, 6.4.6Β and below, 6.2.9Β and below, 6.0.12 and below. FortiProxy 2.0.1 and below, 1.2.9 and below"
      }
    ]
  }
]

Social References

More

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2021-26110