CVE-2021-24006
An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
- Affected products
- Fortimanager
- Fortinet Fortimanager
- < 6.4.4
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.0% (59th percentile)
- NVD status
- Modified
- Published
- 2021-09-06
CVE-2021-24006 at NVD
2 known exploits for CVE-2021-24006
Proof-of-concept code and exploit modules indexed by Sploitus