First published: Thu Dec 09 2021(Updated: )
Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | >=6.3.0<=6.3.15 | |
Fortinet FortiWeb | =6.4.0 | |
Fortinet FortiWeb | =6.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this cybersecurity issue is CVE-2021-36194.
The severity of CVE-2021-36194 is high with a CVSS score of 8.8.
FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 are affected by CVE-2021-36194.
An authenticated attacker can achieve arbitrary code execution via specially crafted requests.
Yes, you can find more information about CVE-2021-36194 at https://fortiguard.com/advisory/FG-IR-21-152.