CVE-2021-36186: Buffer Overflow
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36186?
CVE-2021-36186 is a vulnerability in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below that allows an attacker to execute unauthorized code or commands via crafted HTTP requests.
How severe is CVE-2021-36186?
CVE-2021-36186 has a severity score of 9.8 (Critical).
Which versions of Fortinet FortiWeb are affected by CVE-2021-36186?
CVE-2021-36186 affects Fortinet FortiWeb versions 6.4.0, 6.3.15 and below, and 6.2.5 and below.
How can an attacker exploit CVE-2021-36186?
An attacker can exploit CVE-2021-36186 by sending crafted HTTP requests to the vulnerable Fortinet FortiWeb server.
Is there a fix for CVE-2021-36186?
Yes, updating Fortinet FortiWeb to a version that is not affected by CVE-2021-36186 will fix the vulnerability.