CVE-2021-42753Path Traversal in Fortinet Fortiweb

CWE-22Path Traversal4 documents4 sources
Severity
8.1HIGHNVD
EPSS
0.6%
top 30.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 2
Latest updateFeb 8

Description

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and directory deletion in the device filesystem.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages1 packages

NVDfortinet/fortiweb5.8.06.3.16+1

🔴Vulnerability Details

2
GHSA
GHSA-4h43-2654-6c5f: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 62022-02-08
CVEList
CVE-2021-42753: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 62022-02-02

📋Vendor Advisories

1
Fortinet
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb man...2022-02-02
CVE-2021-42753 — Path Traversal in Fortinet Fortiweb | cvebase