CVE-2021-41014: High severity fortinet fortiweb vulnerability
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-41014?
CVE-2021-41014 is a vulnerability that allows an unauthenticated attacker to make the httpsd daemon unresponsive in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below.
How severe is CVE-2021-41014?
CVE-2021-41014 has a severity score of 7.5 (high).
Which software versions are affected by CVE-2021-41014?
Fortinet FortiWeb versions 6.4.1 and below, 6.3.15 and below are affected by CVE-2021-41014.
How can an attacker exploit CVE-2021-41014?
An attacker can exploit CVE-2021-41014 by sending huge HTTP packets to the httpsd daemon, causing it to become unresponsive.
Is there a fix for CVE-2021-41014?
Fortinet has released patches to address the vulnerability. Users should upgrade to FortiWeb version 6.4.2 or 6.3.16 to mitigate the risk.