CVE Vulnerabilities

CVE-2021-36190

Published: Dec 08, 2021 | Modified: Aug 08, 2023
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A unintended proxy or intermediary (confused deputy) in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.

Affected Software

Name Vendor Start Version End Version
Fortiweb Fortinet 6.0.0 (including) 6.0.7 (including)
Fortiweb Fortinet 6.2.0 (including) 6.2.6 (including)
Fortiweb Fortinet 6.3.0 (including) 6.3.15 (including)
Fortiweb Fortinet 6.1.0 (including) 6.1.0 (including)
Fortiweb Fortinet 6.1.1 (including) 6.1.1 (including)
Fortiweb Fortinet 6.1.2 (including) 6.1.2 (including)
Fortiweb Fortinet 6.4.0 (including) 6.4.0 (including)
Fortiweb Fortinet 6.4.1 (including) 6.4.1 (including)

References