VulnerabilityModified
CVE-2021-43065
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.
HIGH 7.8EPSS 0.43%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- fortinet/fortinac
- Source
- psirt@fortinet.com
References
- https://fortiguard.com/advisory/FG-IR-21-178Vendor Advisory
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-8wx4-g5p9-348hExploit, Third Party Advisory
- https://fortiguard.com/advisory/FG-IR-21-178Vendor Advisory
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-8wx4-g5p9-348hExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.