CVE-2021-42758: Critical severity fortinet fortiwlc vulnerability
Published Dec 8, 2021
·Updated
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.
Affected Software
17 affected components
Fortinet FortiWLC>=8.2.4<=8.2.7
Fortinet FortiWLC>=8.3.0<=8.3.3
Fortinet FortiWLC>=8.5.0<=8.5.5
Fortinet FortiWLC=8.0.5
Fortinet FortiWLC=8.0.6
Fortinet FortiWLC=8.1.2
Fortinet FortiWLC=8.1.3
Fortinet FortiWLC=8.4.0
Fortinet FortiWLC=8.4.1
Fortinet FortiWLC=8.4.2
Fortinet FortiWLC=8.4.4
Fortinet FortiWLC=8.4.5
Fortinet FortiWLC=8.4.6
Fortinet FortiWLC=8.4.7
Fortinet FortiWLC=8.4.8
Fortinet FortiWLC=8.6.0
Fortinet FortiWLC=8.6.1
Remediation
Patch Available
Event History
Dec 8, 2021
CVE Published
via MITRE·10:53 AM
Data Sourced
via MITRE·10:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-42758?
CVE-2021-42758 is an improper access control vulnerability in FortiWLC 8.6.1 and below.
2
How does CVE-2021-42758 impact FortiWLC?
CVE-2021-42758 allows an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights.
3
What is the severity of CVE-2021-42758?
The severity of CVE-2021-42758 is critical with a CVSS score of 8.8.
4
Which versions of FortiWLC are affected by CVE-2021-42758?
FortiWLC versions 8.6.1 and below are affected by CVE-2021-42758.
5
How can I fix CVE-2021-42758?
To fix CVE-2021-42758, update FortiWLC to a version that is not affected.