Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32584

Опубликовано: 17 мар. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functionality by just specifying the correct URL. The vulnerability applies only to limited CGI resources and might allow the unauthorized party to access configuration details.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:fortinet:fortiwlc:*:*:*:*:*:*:*:*
Версия от 8.1.3 (включая) до 8.5.4 (исключая)
cpe:2.3:a:fortinet:fortiwlc:8.6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00093
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
github
11 месяцев назад

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functionality by just specifying the correct URL. The vulnerability applies only to limited CGI resources and might allow the unauthorized party to access configuration details.

EPSS

Процентиль: 26%
0.00093
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284