CVE-2021-42753 — Path Traversal in Fortinet Fortiweb
Severity
8.1HIGHNVD
EPSS
0.6%
top 30.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 2
Latest updateFeb 8
Description
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and directory deletion in the device filesystem.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-4h43-2654-6c5f: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6↗2022-02-08
CVEList▶
CVE-2021-42753: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6↗2022-02-02
📋Vendor Advisories
1Fortinet▶
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb man...↗2022-02-02