CVE-2021-42761: Critical severity fortinet fortiweb vulnerability
A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-42761?
CVE-2021-42761 is a session fixation vulnerability in FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1.
How severe is CVE-2021-42761?
CVE-2021-42761 has a severity rating of 9.8 (Critical).
What is the CWE-ID for CVE-2021-42761?
The CWE-ID for CVE-2021-42761 is CWE-384.
How can a remote attacker exploit CVE-2021-42761?
A remote, unauthenticated attacker may exploit CVE-2021-42761 to infer the session identifier and potentially hijack a user's session.
Is there a fix available for CVE-2021-42761?
Yes, Fortinet has released fixes for CVE-2021-42761. Please refer to the vendor's advisory for the appropriate patches and updates.