CVE-2021-24006: [FortiManager] A restricted admin can access SD-WAN ORCHESTRATOR panel
An improper access control vulnerability [CWE-284] in FortiManager may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
Other sources
An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiManager vulnerability?
The vulnerability ID for this FortiManager vulnerability is CVE-2021-24006.
Which versions of FortiManager are affected by this vulnerability?
FortiManager versions 6.4.0 to 6.4.3 are affected by this vulnerability.
What is the severity level of CVE-2021-24006?
The severity level of CVE-2021-24006 is high, with a CVSS score of 8.8.
What is the impact of this vulnerability?
This vulnerability allows an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
Is there a fix available for this vulnerability?
Yes, a fix for this vulnerability is available in FortiManager version 6.4.4.