CVE-2021-24017: Access Control missing in P&O module assignment vulnerability
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
Other sources
An improper authentication vulnerability [CWE-287] in FortiManager may allow a standard user to assign or un-assign a global policy package via a POST request to flatui/json module.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-24017.
What is the affected software for this vulnerability?
The affected software is Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below.
What is the severity of CVE-2021-24017?
The severity of CVE-2021-24017 is medium (4.3).
How does CVE-2021-24017 impact Fortinet FortiManager?
CVE-2021-24017 allows attackers to assign arbitrary Policy and Object modules via crafted requests to the request handler, which can lead to unauthorized access and potential misuse of the system.
Is there a fix available for CVE-2021-24017?
Yes, Fortinet has released patches to address this vulnerability. It is recommended to update to version 6.2.7 if using FortiManager 6.2.x or to version 6.4.5 if using FortiManager 6.4.x.