First published: Wed Dec 08 2021(Updated: )
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | >=6.0.0<=6.0.7 | |
Fortinet FortiWeb | >=6.2.0<=6.2.5 | |
Fortinet FortiWeb | >=6.3.0<=6.3.15 | |
Fortinet FortiWeb | =6.1.0 | |
Fortinet FortiWeb | =6.1.1 | |
Fortinet FortiWeb | =6.1.2 | |
Fortinet FortiWeb | =6.4.0 | |
Fortinet FortiWeb | =6.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41014 is a vulnerability that allows an unauthenticated attacker to make the httpsd daemon unresponsive in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below.
CVE-2021-41014 has a severity score of 7.5 (high).
Fortinet FortiWeb versions 6.4.1 and below, 6.3.15 and below are affected by CVE-2021-41014.
An attacker can exploit CVE-2021-41014 by sending huge HTTP packets to the httpsd daemon, causing it to become unresponsive.
Fortinet has released patches to address the vulnerability. Users should upgrade to FortiWeb version 6.4.2 or 6.3.16 to mitigate the risk.