Lucene search

K
fortinetFortiGuard LabsFG-IR-21-178
HistoryDec 07, 2021 - 12:00 a.m.

FortiNAC - improper permissions set for tomcat users configuration file

2021-12-0700:00:00
FortiGuard Labs
www.fortiguard.com
17
fortinac
permissions
tomcat
configuration file
vulnerability
cwe-732
authenticated attacker
sensitive data
privilege escalation
admin

EPSS

0.001

Percentile

17.8%

An incorrect permission assignment for a critical resource vulnerability [CWE-732] in FortiNAC may allow an authenticated attacker to access sensitive system data and, as a consequence, raise the authenticated user’s privilege to admin.

EPSS

0.001

Percentile

17.8%

Related for FG-IR-21-178