CVE-2021-41027: Buffer Overflow
Published Dec 8, 2021
·Updated
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.
Affected Software
2 affected components
Fortinet FortiWeb=6.4.0
Fortinet FortiWeb=6.4.1
Remediation
Patch Available
Event History
Dec 8, 2021
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-41027.
2
What is the severity of CVE-2021-41027?
The severity of CVE-2021-41027 is high, with a severity value of 7.8.
3
What is the affected software?
Fortinet FortiWeb version 6.4.1 and 6.4.0 are affected.
4
How can an attacker exploit CVE-2021-41027?
An authenticated attacker can execute unauthorized code or commands by loading crafted certificates into the device.
5
Is there a fix for CVE-2021-41027?
Updating Fortinet FortiWeb to a version that is not vulnerable, such as 6.4.2 or later, will fix the vulnerability.