CVE-2021-36195: OS Command Injection
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36195?
CVE-2021-36195 is a vulnerability in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 that allows an authenticated attacker to execute arbitrary commands on the underlying system shell.
How severe is CVE-2021-36195?
CVE-2021-36195 has a severity score of 8.8 which is classified as critical.
How can an attacker exploit CVE-2021-36195?
An attacker can exploit CVE-2021-36195 by sending specially crafted commands to the command line interpreter of FortiWeb.
Which versions of FortiWeb are affected by CVE-2021-36195?
FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 are affected by CVE-2021-36195.
Is there a fix for CVE-2021-36195?
Yes, it is recommended to upgrade to a fixed version of FortiWeb. Please refer to the Fortinet advisory for more information.