PT-2021-7570 · Fortinet · Fortiweb

Published

2021-12-07

·

Updated

2021-12-10

·

CVE-2021-36194

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiWeb versions 6.3.0 through 6.3.15 FortiWeb versions 6.4.0 through 6.4.1
Description The issue is related to multiple stack-based buffer overflows in the API controllers, which may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests. This can be exploited by a remote attacker to execute arbitrary code using a specially crafted request.
Recommendations For FortiWeb versions 6.3.0 through 6.3.15, update to a version that fixes the buffer overflow issue in the API controllers. For FortiWeb versions 6.4.0 through 6.4.1, update to a version that fixes the buffer overflow issue in the API controllers. As a temporary workaround, consider restricting access to the API controllers to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00093
CVE-2021-36194

Affected Products

Fortiweb