Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-24008


An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, FortiVoice version 6.0.6 and below, FortiRecorder version 6.0.3 and below and FortiMail version 6.4.1 and below, version 6.2.4 and below, version 6.0.9 and below may allow a remote, unauthenticated attacker to obtain potentially sensitive software-version information by reading a JavaScript file.


Published

2025-03-28T11:15:36.620

Last Modified

2025-07-24T19:57:26.330

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-200
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortimail < 6.0.10 Yes
Application fortinet fortimail < 6.2.5 Yes
Application fortinet fortimail < 6.4.2 Yes
Application fortinet fortiddos < 5.4.3 Yes
Application fortinet fortivoice < 6.0.7 Yes
Application fortinet fortirecorder < 6.0.4 Yes
Application fortinet fortiddos-cm 4.7.0 Yes
Application fortinet fortiddos-cm 5.0.0 Yes
Application fortinet fortiddos-cm 5.1.0 Yes
Application fortinet fortiddos-cm 5.2.0 Yes
Application fortinet fortiddos-cm 5.3.0 Yes

References