CVE-2021-36190: Medium severity fortinet fortiweb vulnerability
Published Dec 8, 2021
·Updated
A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.
Affected Software
8 affected components
Fortinet FortiWeb>=6.0.0<=6.0.7
Fortinet FortiWeb>=6.2.0<=6.2.6
Fortinet FortiWeb>=6.3.0<=6.3.15
Fortinet FortiWeb=6.1.0
Fortinet FortiWeb=6.1.1
Fortinet FortiWeb=6.1.2
Fortinet FortiWeb=6.4.0
Fortinet FortiWeb=6.4.1
Remediation
Patch Available
Event History
Dec 8, 2021
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Fortinet FortiWeb vulnerability?
The vulnerability ID for this Fortinet FortiWeb vulnerability is CVE-2021-36190.
2
What is the severity level of CVE-2021-36190?
The severity level of CVE-2021-36190 is medium.
3
Which versions of Fortinet FortiWeb are affected by CVE-2021-36190?
Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below, 6.2.6 and below, 6.1.2 and below, and 6.0.7 and below are affected by CVE-2021-36190.
4
How can an attacker exploit this vulnerability?
An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests to gain unauthorized access to protected hosts.
5
Where can I find more information about CVE-2021-36190?
You can find more information about CVE-2021-36190 on the FortiGuard website: https://fortiguard.com/advisory/FG-IR-21-123