CVE-2021-43071Out-of-bounds Write in Fortinet Fortiweb

Severity
8.8HIGHNVD
EPSS
0.5%
top 34.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateDec 10

Description

A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortiweb6.2.06.2.6+3
CVEListV5fortinet/fortinet_fortiwebFortiWeb 6.4.1, 6.4.0, 6.3.16, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-23cq-6739-c6x5: A heap-based buffer overflow in Fortinet FortiWeb version 62021-12-10
CVEList
CVE-2021-43071: A heap-based buffer overflow in Fortinet FortiWeb version 62021-12-09

📋Vendor Advisories

1
Fortinet
A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and b...2021-12-09
CVE-2021-43071 — Out-of-bounds Write in Fortinet | cvebase