CVE-2021-43073: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43073?
CVE-2021-43073 is a vulnerability that allows an attacker to execute unauthorized code or commands via crafted HTTP requests in Fortinet FortiWeb.
What is the severity of CVE-2021-43073?
CVE-2021-43073 has a severity rating of 8.8 (high).
Which versions of Fortinet FortiWeb are affected by CVE-2021-43073?
Fortinet FortiWeb versions 6.4.1 and 6.4.0, versions 6.3.15 and below, and versions 6.2.6 and below are affected by CVE-2021-43073.
How can an attacker exploit CVE-2021-43073?
An attacker can exploit CVE-2021-43073 by sending crafted HTTP requests that contain malicious code or commands.
Is there a fix for CVE-2021-43073?
Yes, Fortinet has released patches to fix CVE-2021-43073. It is recommended to update to the latest version of Fortinet FortiWeb.