Lucene search

K
fortinetFortiGuard LabsFG-IR-21-059
HistoryAug 03, 2021 - 12:00 a.m.

FortiManager & FortiAnalyzer - Improper access control on the administrators account list

2021-08-0300:00:00
FortiGuard Labs
www.fortiguard.com
18
fortimanager
fortianalyzer
access control
vulnerability
remote attacker
authenticated attacker
user profile
adoms
configuration.

EPSS

0.001

Percentile

22.7%

An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.

EPSS

0.001

Percentile

22.7%

Related for FG-IR-21-059