SB2021090715 - Multiple vulnerabilities in FortiOS
Published: September 7, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper access control (CVE-ID: CVE-2021-32600)
The vulnerability allows a local user to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions. A local authenticated user assigned to a specific VDOM can retrieve
other VDOMs information such as the admin account list and the network
interface list.
2) Code Injection (CVE-ID: CVE-2021-36169)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation within the debug functionality in FortiGate. A local privileged user can execute unauthorized code or commands via specific
chains of `print str` and `cmd mem` cli commands to, respectively, read and write hexadecimal values to any memory address.
Remediation
Install update from vendor's website.