CVE-2021-41013
published 2021-12-08CVE-2021-41013: An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.94%
56.8th percentile
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 6.3.0 – 6.3.15 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78rc-hmp8-p646: An improper access control vulnerability [CWE-284] in FortiWeb versions 6
ghsa_unreviewed·2021-12-09
CVE-2021-41013 [MEDIUM] CWE-863 GHSA-78rc-hmp8-p646: An improper access control vulnerability [CWE-284] in FortiWeb versions 6
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
Fortinet
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Repo...
vendor_fortinet·2021-12-08·CVSS 5.3
CVE-2021-41013 [MEDIUM] CWE-863 An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Repo...
FG-IR-21-138: An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Repo...
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
CVEs: CVE-2021-41013
CWEs: CWE-863
CVSS: 5.3 (medium)
Affected products: FortiWeb
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-08
Published