CVE-2021-43206: Medium severity fortinet fortiproxy ssl vpn webmode vulnerability
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated HTTP status codes pages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43206?
CVE-2021-43206 is a vulnerability in Fortinet FortiOS and FortiProxy that allows malicious webservers to retrieve a web proxy's client username and IP.
Which software versions are affected by CVE-2021-43206?
Fortinet FortiOS versions 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x, and FortiProxy versions 7.0.0 through 7.0.1, 2.0.x are affected by CVE-2021-43206.
What is the severity of CVE-2021-43206?
CVE-2021-43206 has a severity score of 4.3 (medium).
How can a malicious webserver exploit CVE-2021-43206?
A malicious webserver can exploit CVE-2021-43206 by triggering a server-generated error message that contains sensitive information, allowing it to retrieve a web proxy's client username and IP.
Is there a fix available for CVE-2021-43206?
Yes, Fortinet has released patches to address the vulnerability. It is recommended to update to the latest version of Fortinet FortiOS or FortiProxy to mitigate the risk.