First published: Wed Dec 08 2021(Updated: )
A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.
Credit: psirt@fortinet.com psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | >=6.0.0<=6.0.7 | |
Fortinet FortiWeb | >=6.2.0<=6.2.6 | |
Fortinet FortiWeb | >=6.3.0<=6.3.15 | |
Fortinet FortiWeb | =6.1.0 | |
Fortinet FortiWeb | =6.1.1 | |
Fortinet FortiWeb | =6.1.2 | |
Fortinet FortiWeb | =6.4.0 | |
Fortinet FortiWeb | =6.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Fortinet FortiWeb vulnerability is CVE-2021-36190.
The severity level of CVE-2021-36190 is medium.
Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below, 6.2.6 and below, 6.1.2 and below, and 6.0.7 and below are affected by CVE-2021-36190.
An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests to gain unauthorized access to protected hosts.
You can find more information about CVE-2021-36190 on the FortiGuard website: https://fortiguard.com/advisory/FG-IR-21-123