CVE Vulnerabilities

CVE-2021-43074

Improper Verification of Cryptographic Signature

Published: Feb 16, 2023 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
FortiproxyFortinet1.0.0 (including)2.0.8 (excluding)
FortiproxyFortinet7.0.0 (including)7.0.2 (excluding)
FortiwebFortinet6.0.0 (including)6.3.17 (excluding)
FortiwebFortinet6.4.0 (including)7.0.0 (excluding)
FortiosFortinet6.0.0 (including)6.4.9 (excluding)
FortiosFortinet7.0.0 (including)7.0.4 (excluding)
FortiswitchFortinet6.0.0 (including)6.4.11 (excluding)
FortiswitchFortinet7.0.0 (including)7.0.4 (excluding)

References