Aller au contenu

Fiche vulnérabilité

CVE-2021-42756 : faille critique fortinet fortiweb (CVSS 9.8)

Description

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
16 févr. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • fortinet fortiweb

Références

Rechercher une autre vulnérabilité dans la base CVE