imPC@ndo IT

Tracker / CVE-2021-42758

CVE-2021-42758

High 8.8

An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.

Affected products and versions

fortinet fortiwlc
fortinet fortiwlc · 8.2.4 → 8.2.7
fortinet fortiwlc · 8.3.0 → 8.3.3
fortinet fortiwlc · 8.5.0 → 8.5.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References