CVE-2021-32588
A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated at...
Affects 1 product across 1 vendor.
Software contains embedded passwords or keys that cannot be changed by the administrator.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, and versions 5.1.x and 5.0.x allows remote, unauthenticated attackers to execute unauthorized commands as root due to hard-coded credentials in the Tomcat Manager.
BSID: BS-2021-GLOBAL-275553-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2021-32588?
What is the CVSS score for CVE-2021-32588?
Is CVE-2021-32588 actively exploited?
How do I remediate CVE-2021-32588?
What systems are affected by CVE-2021-32588?
| CVE ID | CVE-2021-32588 |
|---|---|
| BSID | BS-2021-GLOBAL-275553-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2021-08-18 |
| Last Modified | 2026-06-17 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unauthorized commands as root by uploading and deploying malicious web application archive files using the default hard-coded Tomcat Manager username and password.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the use of hard-coded credentials for the Tomcat Manager, which can be exploited by an attacker to upload and deploy malicious web application archive files, leading to unauthorized command execution with root privileges.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortinet | Fortiportal | ≥ 5.0.0, ≤ 5.0.3 ≥ 5.1.0, ≤ 5.1.2 ≥ 5.2.0, ≤ 5.2.5 ≥ 5.3.0, ≤ 5.3.5 ≥ 6.0.0, ≤ 6.0.4 |
No patch URL on record. Monitor vendor security advisories directly.
| CISA known-exploited | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
AI Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 320a67253077f1a81764ba6318cfc9fc5334875506f268e14711e8a7249a17dedcc9d9d08a9bc7c0997cf1daee8890e856ad16d828bb9b2640763dd6174b9253 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Create a free account →