Severity
7.2HIGH
EPSS
0.5%
top 34.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 2
Latest updateAug 25

Description

Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages11 packages

NVDfortinet/fortiweb5.0.06.2.6+2
CVEListV5fortinet/fortiweb6.4.06.4.1+1
CVEListV5fortinet/fortiadc6.2.06.2.2+8
CVEListV5fortinet/fortindr1.5.01.5.3+4
CVEListV5fortinet/fortiddos5.6.05.6.1+11

🔴Vulnerability Details

3
GHSA
GHSA-xfch-762x-q3v9: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 62022-02-08
CVEList
CVE-2021-36193: Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 62022-02-02
GHSA
Directory Traversal in Archive_Tar2021-08-09

📋Vendor Advisories

4
CISA
PEAR Archive_Tar Improper Link Resolution Vulnerability2022-08-25
Fortinet
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate...2022-02-02
Red Hat
php-pear: Directory traversal vulnerability2021-07-30
Drupal
Drupal core - Critical - Third-party libraries - SA-CORE-2021-0012021-01-20
CVE-2021-36193 (HIGH CVSS 7.2) | Multiple stack-based buffer overflo | cvebase.io