CVE Vulnerabilities

CVE-2021-36190

Published: Dec 08, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A unintended proxy or intermediary (confused deputy) in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.

Affected Software

NameVendorStart VersionEnd Version
FortiwebFortinet6.0.0 (including)6.0.7 (including)
FortiwebFortinet6.2.0 (including)6.2.6 (including)
FortiwebFortinet6.3.0 (including)6.3.15 (including)
FortiwebFortinet6.1.0 (including)6.1.0 (including)
FortiwebFortinet6.1.1 (including)6.1.1 (including)
FortiwebFortinet6.1.2 (including)6.1.2 (including)
FortiwebFortinet6.4.0 (including)6.4.0 (including)
FortiwebFortinet6.4.1 (including)6.4.1 (including)

References