CVE-2021-43071: Buffer Overflow
Published Dec 9, 2021
·Updated
A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller.
Affected Software
4 affected components
Fortinet FortiWeb>=6.2.0<=6.2.6
Fortinet FortiWeb>=6.3.0<=6.3.16
Fortinet FortiWeb=6.4.0
Fortinet FortiWeb=6.4.1
Remediation
Patch Available
Event History
Dec 9, 2021
CVE Published
via MITRE·09:18 AM
Data Sourced
via MITRE·09:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-43071?
CVE-2021-43071 is a heap-based buffer overflow vulnerability in Fortinet FortiWeb.
2
What versions of Fortinet FortiWeb are affected by CVE-2021-43071?
Fortinet FortiWeb versions 6.4.1, 6.4.0, 6.3.15 and below, and 6.2.6 and below are affected.
3
What is the severity of CVE-2021-43071?
CVE-2021-43071 has a severity score of 8.8, which is classified as high.
4
How can an attacker exploit CVE-2021-43071?
An attacker can exploit CVE-2021-43071 by sending crafted HTTP requests to the LogReport API controller.
5
Is there a fix available for CVE-2021-43071?
Yes, Fortinet has released patches and updates to fix CVE-2021-43071. Please refer to the Fortinet advisory for more information.