CVE-2021-32587: Medium severity fortinet fortianalyzer vulnerability
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32587?
CVE-2021-32587 is an improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface.
How does CVE-2021-32587 impact FortiManager and FortiAnalyzer?
CVE-2021-32587 allows a remote and authenticated attacker with a restricted user profile to retrieve the list of administrative users of other ADOMs.
Which versions of FortiManager and FortiAnalyzer are affected by CVE-2021-32587?
FortiManager versions 6.0.11 and below, 6.2.8 and below, 6.4.5 and below, and FortiAnalyzer versions 5.6.11 and below, 6.0.11 and below, 6.2.8 and below, 6.4.5 and below are affected by CVE-2021-32587.
What is the severity of CVE-2021-32587?
CVE-2021-32587 has a severity rating of medium with a CVSS score of 4.3.
How can I mitigate CVE-2021-32587 in FortiManager and FortiAnalyzer?
Apply the necessary security patches or updates provided by Fortinet to fix the CVE-2021-32587 vulnerability.