Vulnerability Details CVE-2021-32587
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.0%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2021-32587
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.0
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.1
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.10
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.11
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.2
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.3
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.4
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.5
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.6
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.7
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.8
-
cpe:2.3:a:fortinet:fortianalyzer:5.6.9
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.0
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.1
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.10
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.11
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.2
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.3
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.4
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.5
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.6
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.7
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.8
-
cpe:2.3:a:fortinet:fortianalyzer:6.0.9
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.0
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.1
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.10
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.11
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.12
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.2
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.3
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.4
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.5
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.6
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.7
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.8
-
cpe:2.3:a:fortinet:fortianalyzer:6.2.9
-
cpe:2.3:a:fortinet:fortianalyzer:6.4.0
-
cpe:2.3:a:fortinet:fortianalyzer:6.4.1
-
cpe:2.3:a:fortinet:fortianalyzer:6.4.2
-
cpe:2.3:a:fortinet:fortianalyzer:6.4.3
-
cpe:2.3:a:fortinet:fortianalyzer:6.4.4
-
cpe:2.3:a:fortinet:fortianalyzer:6.4.5
-
cpe:2.3:a:fortinet:fortianalyzer:7.0.0
-
cpe:2.3:a:fortinet:fortimanager:5.6.0
-
cpe:2.3:a:fortinet:fortimanager:5.6.1
-
cpe:2.3:a:fortinet:fortimanager:5.6.10
-
cpe:2.3:a:fortinet:fortimanager:5.6.11
-
cpe:2.3:a:fortinet:fortimanager:5.6.2
-
cpe:2.3:a:fortinet:fortimanager:5.6.3
-
cpe:2.3:a:fortinet:fortimanager:5.6.4
-
cpe:2.3:a:fortinet:fortimanager:5.6.5
-
cpe:2.3:a:fortinet:fortimanager:5.6.6
-
cpe:2.3:a:fortinet:fortimanager:5.6.7
-
cpe:2.3:a:fortinet:fortimanager:5.6.8
-
cpe:2.3:a:fortinet:fortimanager:5.6.9
-
cpe:2.3:a:fortinet:fortimanager:6.0.0
-
cpe:2.3:a:fortinet:fortimanager:6.0.1
-
cpe:2.3:a:fortinet:fortimanager:6.0.10
-
cpe:2.3:a:fortinet:fortimanager:6.0.11
-
cpe:2.3:a:fortinet:fortimanager:6.0.2
-
cpe:2.3:a:fortinet:fortimanager:6.0.3
-
cpe:2.3:a:fortinet:fortimanager:6.0.4
-
cpe:2.3:a:fortinet:fortimanager:6.0.5
-
cpe:2.3:a:fortinet:fortimanager:6.0.6
-
cpe:2.3:a:fortinet:fortimanager:6.0.7
-
cpe:2.3:a:fortinet:fortimanager:6.0.8
-
cpe:2.3:a:fortinet:fortimanager:6.0.9
-
cpe:2.3:a:fortinet:fortimanager:6.2.0
-
cpe:2.3:a:fortinet:fortimanager:6.2.1
-
cpe:2.3:a:fortinet:fortimanager:6.2.10
-
cpe:2.3:a:fortinet:fortimanager:6.2.11
-
cpe:2.3:a:fortinet:fortimanager:6.2.12
-
cpe:2.3:a:fortinet:fortimanager:6.2.13
-
cpe:2.3:a:fortinet:fortimanager:6.2.2
-
cpe:2.3:a:fortinet:fortimanager:6.2.3
-
cpe:2.3:a:fortinet:fortimanager:6.2.4
-
cpe:2.3:a:fortinet:fortimanager:6.2.5
-
cpe:2.3:a:fortinet:fortimanager:6.2.6
-
cpe:2.3:a:fortinet:fortimanager:6.2.7
-
cpe:2.3:a:fortinet:fortimanager:6.2.8
-
cpe:2.3:a:fortinet:fortimanager:6.2.9
-
cpe:2.3:a:fortinet:fortimanager:6.4.0
-
cpe:2.3:a:fortinet:fortimanager:6.4.1
-
cpe:2.3:a:fortinet:fortimanager:6.4.2
-
cpe:2.3:a:fortinet:fortimanager:6.4.3
-
cpe:2.3:a:fortinet:fortimanager:6.4.4
-
cpe:2.3:a:fortinet:fortimanager:6.4.5
-
cpe:2.3:a:fortinet:fortimanager:7.0.0