CVE-2021-24006 is an improper access control vulnerability affecting FortiManager versions 6.4.0 through 6.4.3. The flaw allows an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel by directly requesting its URL, bypassing intended authorization restrictions in the web application. Based on the available advisory information, the issue is a failure to properly enforce role-based access controls on the SD-WAN Orchestrator interface.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal Python proof-of-concept for CVE-2021-24006 (FortiManager improper access control) plus a README describing affected versions and mitigations. Structure: - README.md: States CVE-2021-24006 affects FortiManager 6.4.0–6.4.3 and allows an authenticated restricted admin to directly access the SD-WAN Orchestrator panel URL without proper authorization checks. Mentions the critical path /fortiwan/maintenance/controller_configuration and recommends upgrading to 6.4.4+ or 7.0.0+. - exploit.py: Uses requests.Session() to (1) disable TLS warnings and skip certificate verification, (2) POST credentials to /logincheck with ajax=1, username, secretkey, then (3) GET /fortiwan/maintenance/controller_configuration. It declares success when the response is HTTP 200 and contains the string 'SD-WAN', printing the first 500 characters of the response. Capabilities: - Authenticated web exploitation/verification of an authorization bypass (no RCE). - Requires valid restricted-admin credentials; does not attempt credential discovery. - Fingerprint/confirmation logic is simple (status code + substring match). Notable observables: - Hardcoded example target base URL: https://192.168.1.100 - Endpoints: /logincheck and /fortiwan/maintenance/controller_configuration - Hardcoded example credentials in code (restricted_admin / senha123), intended to be replaced by the operator.
Repository contains a minimal Python Proof-of-Concept for CVE-2021-24006 (FortiManager improper access control affecting 6.4.0–6.4.3). Structure: (1) README.md describing the vulnerability, affected versions, prerequisites (SD-WAN Orchestrator installed; restricted admin credentials), and the critical URL path; (2) exploit.py implementing the PoC. Exploit flow in exploit.py: disables urllib3 TLS warnings and sets verify=False (accepts self-signed certs), creates a requests.Session to retain cookies, POSTs credentials to /logincheck with parameters {ajax=1, username, secretkey}, checks for 'error=0' in the response to confirm login, then GETs /fortiwan/maintenance/controller_configuration. If HTTP 200 and the response contains 'SD-WAN', it reports unauthorized access and prints the first 500 characters of the page. Capabilities are limited to demonstrating/validating the authorization bypass (no RCE, no persistence, no lateral movement). The only network targets are the FortiManager HTTPS endpoints used for login and the restricted SD-WAN Orchestrator page.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.