CVE-2021-42753: Path Traversal
Published Feb 2, 2022
·Updated
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and directory deletion in the device filesystem.
Affected Software
2 affected components
Fortinet FortiWeb>=5.8.0<6.3.16
Fortinet FortiWeb>=6.4.0<6.4.2
Event History
Feb 2, 2022
CVE Published
via MITRE·10:46 AM
Data Sourced
via MITRE·10:46 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-42753.
2
What is the severity of CVE-2021-42753?
The severity of CVE-2021-42753 is high (8.1).
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-22.
4
Which Fortinet FortiWeb versions are affected by this vulnerability?
FortiWeb management interface versions 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x, and 5.8.x are affected.
5
How can an attacker exploit CVE-2021-42753?
An authenticated attacker can exploit this vulnerability to perform arbitrary file and directory deletion.