CVE-2021-42756
CRITICALFortinet Fortiweb < 6.0.8 - Out-of-Bounds Write
Title source: ruleDescription
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.
Exploits (1)
References (1)
Scores
CVSS v3
9.8
EPSS
0.6422
EPSS Percentile
98.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-121
CWE-787
Status
published
Products (1)
fortinet/fortiweb
5.6.0 - 6.0.8
Published
Feb 16, 2023
Tracked Since
Feb 18, 2026