CVE-2021-32584 Information

Description

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0 version 8.5.3 and below version 8.4.8 and below version 8.3.3 and below version 8.2.7 to 8.2.4 version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functionality by just specifying the correct URL. The vulnerability applies only to limited CGI resources and might allow the unauthorized party to access configuration details.

Reference

https://fortiguard.fortinet.com/psirt/FG-IR-20-138

Share on: