CVE-2021-42756: Buffer Overflow
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-42756?
CVE-2021-42756 refers to multiple stack-based buffer overflow vulnerabilities in the proxy daemon of FortiWeb.
What is the severity of CVE-2021-42756?
CVE-2021-42756 has a severity score of 9.8, which is considered critical.
How can an attacker exploit CVE-2021-42756?
An unauthenticated remote attacker can achieve arbitrary code execution by exploiting the stack-based buffer overflow vulnerabilities in the proxy daemon of FortiWeb.
Which versions of FortiWeb are affected by CVE-2021-42756?
FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, and 6.4 all versions are affected by CVE-2021-42756.
Is there a patch available for CVE-2021-42756?
Yes, Fortinet has released patches to mitigate the vulnerabilities in FortiWeb. Please refer to the official Fortinet website for patch information.