Improper access control in FortiProxy and FortiOS - CVE-2021-26110
Published: December 7, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in the autod daemon. A local user can bypass implemented security restrictions and escalate privileges on the systems to uper_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.
Affected software
FortiOS
How to mitigate CVE-2021-26110
FortiOS - addressed in versions 6.0.13, 6.2.10, 6.4.7, 7.0.1