CVE-2021-32594

An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper with the underlying system's files via the upload of specifically crafted files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
fortinetCNA
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:U/RC:C
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
fortinetfortiportal
4.0.0 ≤
𝑥
≤ 4.0.4
fortinetfortiportal
4.1.0 ≤
𝑥
≤ 4.1.2
fortinetfortiportal
4.2.0 ≤
𝑥
≤ 4.2.4
fortinetfortiportal
5.0.0 ≤
𝑥
≤ 5.0.3
fortinetfortiportal
5.1.0 ≤
𝑥
≤ 5.1.2
fortinetfortiportal
5.2.0 ≤
𝑥
< 5.2.6
fortinetfortiportal
5.3.0 ≤
𝑥
< 5.3.6
fortinetfortiportal
6.0.0 ≤
𝑥
< 6.0.5
𝑥
= Vulnerable software versions