CVE-2021-41013: Medium severity fortinet fortiweb vulnerability
Published Dec 8, 2021
·Updated
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
Affected Software
3 affected components
Fortinet FortiWeb>=6.3.0<=6.3.15
Fortinet FortiWeb=6.4.0
Fortinet FortiWeb=6.4.1
Remediation
Patch Available
Event History
Dec 8, 2021
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-41013.
2
What is the severity of CVE-2021-41013?
The severity of CVE-2021-41013 is medium with a score of 5.3.
3
Which versions of FortiWeb are affected by CVE-2021-41013?
FortiWeb versions 6.4.1 and below and 6.3.15 and below are affected by CVE-2021-41013.
4
How can an unauthorized user exploit the vulnerability?
An unauthorized user can exploit the vulnerability by accessing the Log reports via their URLs in the Report Browse section of Log & Report.
5
Is there a fix available for CVE-2021-41013?
Yes, Fortinet has released patches to fix CVE-2021-41013. Please refer to the FortiGuard advisory for more information.