#VU58630 Improper access control in FortiOS and FortiProxy - CVE-2021-26110
Published: December 7, 2021
FortiOS
FortiProxy
Fortinet, Inc
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in the autod daemon. A local user can bypass implemented security restrictions and escalate privileges on the systems to uper_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.