Vulnerability Description
An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDOMs using specific CLI commands.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | >= 6.2.0, < 6.4.9 |
References
- https://fortiguard.com/psirt/FG-IR-21-147Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-21-147Vendor Advisory
FAQ
What is CVE-2021-41032?
CVE-2021-41032 is a vulnerability with a CVSS score of 6.3 (MEDIUM). An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive inform...
How severe is CVE-2021-41032?
CVE-2021-41032 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41032?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortios.