CVE-2021-43074: Medium severity fortinet fortiproxy ssl vpn webmode vulnerability
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-43074 vulnerability?
CVE-2021-43074 is an improper verification of cryptographic signature vulnerability in FortiWeb, FortiOS, and FortiSwitch products.
Which products are affected by CVE-2021-43074 vulnerability?
FortiWeb versions 6.4 and below, FortiOS versions 7.0.3 and below, and FortiSwitch versions 7.0.3 and below are affected by CVE-2021-43074 vulnerability.
What is the severity of CVE-2021-43074 vulnerability?
CVE-2021-43074 vulnerability has a severity score of 4.3 (medium).
How can I fix CVE-2021-43074 vulnerability in FortiWeb?
To fix CVE-2021-43074 vulnerability in FortiWeb, upgrade to a version higher than 6.4.8.
Where can I find more information about CVE-2021-43074 vulnerability?
More information about CVE-2021-43074 vulnerability can be found at the following link: [FortiGuard Security Advisory FG-IR-21-126](https://fortiguard.com/psirt/FG-IR-21-126)