← Back

CVE-2021-32584

nvd nist
Published: Mar 17, 2025Modified: Jul 24, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: psirt@fortinet.com (Secondary)

Description

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functionality by just specifying the correct URL. The vulnerability applies only to limited CGI resources and might allow the unauthorized party to access configuration details.

Affected (2)

Products: Fortinet: Fortiwlc
1 product
Fortiwlc
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 8.1.3 to 8.5.4
Version 8.6.0

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.