← Back

CVE-2021-24008

nvd nist
Published: Mar 28, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: psirt@fortinet.com (Secondary)

Description

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, FortiVoice version 6.0.6 and below, FortiRecorder version 6.0.3 and below and FortiMail version 6.4.1 and below, version 6.2.4 and below, version 6.0.9 and below may allow a remote, unauthenticated attacker to obtain potentially sensitive software-version information by reading a JavaScript file.

Affected (11)

5 products
Fortimail
Fortiddos
Fortivoice
Fortirecorder
Fortiddos Cm
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.0.0 to 6.0.10
From 6.2.0 to 6.2.5
From 6.4.0 to 6.4.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.4.0 to 5.4.3
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.0.0 to 6.0.7
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.0.0 to 6.0.4
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
Version 4.7.0
Version 5.0.0
Version 5.1.0
Version 5.2.0
Version 5.3.0

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.