CVE Vulnerabilities

CVE-2021-43074

Improper Verification of Cryptographic Signature

Published: Feb 16, 2023 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Fortiproxy Fortinet 1.0.0 (including) 2.0.8 (excluding)
Fortiproxy Fortinet 7.0.0 (including) 7.0.2 (excluding)
Fortiweb Fortinet 6.0.0 (including) 6.3.17 (excluding)
Fortiweb Fortinet 6.4.0 (including) 7.0.0 (excluding)
Fortios Fortinet 6.0.0 (including) 6.4.9 (excluding)
Fortios Fortinet 7.0.0 (including) 7.0.4 (excluding)
Fortiswitch Fortinet 6.0.0 (including) 6.4.11 (excluding)
Fortiswitch Fortinet 7.0.0 (including) 7.0.4 (excluding)

References