CVE-2021-41014
published 2021-12-08CVE-2021-41014: A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.12%
62.3th percentile
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 6.0.0 – 6.0.7 | — |
| fortinet | fortiweb | 6.2.0 – 6.2.5 | — |
| fortinet | fortiweb | 6.3.0 – 6.3.15 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthentic...
vendor_fortinet·2021-12-08·CVSS 7.5
CVE-2021-41014 [HIGH] CWE-400 A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthentic...
FG-IR-21-131: A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthentic...
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
CVEs: CVE-2021-41014
CWEs: CWE-400
CVSS: 7.5 (high)
Affected products: FortiWeb, Fortinet
GHSA
GHSA-62hx-qw5f-w62x: A uncontrolled resource consumption in Fortinet FortiWeb version 6
ghsa_unreviewed·2021-12-09
CVE-2021-41014 [HIGH] CWE-400 GHSA-62hx-qw5f-w62x: A uncontrolled resource consumption in Fortinet FortiWeb version 6
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-08
Published