CVE-2021-36182: OS Command Injection
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36182?
CVE-2021-36182 is rated as high severity due to the potential for unauthorized code execution.
How do I fix CVE-2021-36182?
To fix CVE-2021-36182, upgrade Fortinet FortiWeb to version 6.3.14 or later.
What impacts can CVE-2021-36182 have on my system?
CVE-2021-36182 can allow attackers to execute arbitrary commands on the affected Fortinet FortiWeb instances.
Which versions of Fortinet FortiWeb are affected by CVE-2021-36182?
Versions of Fortinet FortiWeb from 6.2.4 and below, as well as those from 6.3.0 to 6.3.13, are affected by CVE-2021-36182.
Is CVE-2021-36182 a common vulnerability?
CVE-2021-36182 is a notable vulnerability within the Fortinet FortiWeb software, emphasizing the importance of regular security updates.