CVE-2021-36169: Debug commands allow memory manipulation
A debug functionality in FortiGate may allow a privileged user to execute unauthorized code or commands via specificchains of print str and cmd mem cli commands to, respectively, read and write hexadecimal values to any memory address.
Other sources
A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36169?
CVE-2021-36169 is classified as a high severity vulnerability due to its potential to allow unauthorized code execution.
How do I fix CVE-2021-36169?
To fix CVE-2021-36169, upgrade FortiOS to a version that is not affected by this vulnerability.
Which versions of FortiOS are impacted by CVE-2021-36169?
CVE-2021-36169 affects multiple versions of FortiOS, including 5.6.0 to 5.6.14, 6.0.0 to 6.0.14, 6.2.0 to 6.2.10, 6.4.0 to 6.4.7, and 7.0.0.
What types of attacks can be executed using CVE-2021-36169?
Exploitation of CVE-2021-36169 can allow a privileged user to read and write to any memory address, potentially enabling various malicious attacks.
Who is primarily affected by CVE-2021-36169?
Organizations using affected versions of FortiGate devices and FortiOS software are primarily at risk from CVE-2021-36169.