← All CVEs

CVE-2021-42756

critical · 9.8

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

9.8
CVSS
35.0%
EPSS (exploit prob.)
98th
EPSS percentile
2023-02-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121CWE-787

Affected products

VendorProductAffected versions
fortinetfortiweb>= 5.6.0, < 6.0.8
fortinetfortiweb>= 6.1.0, < 6.1.3
fortinetfortiweb>= 6.2.0, < 6.2.7
fortinetfortiweb>= 6.3.0, < 6.3.17
fortinetfortiweb>= 6.4.0, <= 6.4.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-42756