CVE-2021-41026: Path Traversal
Published Apr 6, 2022
·Updated
A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected Software
2 affected components
Fortinet FortiWeb>=6.3.0<6.3.16
Fortinet FortiWeb>=6.4.0<6.4.2
Event History
Apr 6, 2022
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-41026.
2
What is the severity of CVE-2021-41026?
The severity of CVE-2021-41026 is medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2021-41026?
FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 are affected by CVE-2021-41026.
4
How can an attacker exploit CVE-2021-41026?
An authenticated attacker can exploit CVE-2021-41026 by sending specially crafted web requests to retrieve arbitrary files from the underlying filesystem.
5
Is there a fix for CVE-2021-41026?
Yes, Fortinet has released fixes for CVE-2021-41026. It is recommended to update to FortiWeb versions 6.3.16 or 6.4.2 to mitigate this vulnerability.