PT-2021-7570 · Fortinet · Fortiweb
Published
2021-12-07
·
Updated
2021-12-10
·
CVE-2021-36194
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiWeb versions 6.3.0 through 6.3.15
FortiWeb versions 6.4.0 through 6.4.1
Description
The issue is related to multiple stack-based buffer overflows in the API controllers, which may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests. This can be exploited by a remote attacker to execute arbitrary code using a specially crafted request.
Recommendations
For FortiWeb versions 6.3.0 through 6.3.15, update to a version that fixes the buffer overflow issue in the API controllers.
For FortiWeb versions 6.4.0 through 6.4.1, update to a version that fixes the buffer overflow issue in the API controllers.
As a temporary workaround, consider restricting access to the API controllers to minimize the risk of exploitation.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiweb