CVE-2021-42756
CRITICAL 9.8EPSS 35.0%
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 34.98% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2023-02-16
- Updated
- 2024-10-23
Proof-of-concept exploits (1)
- 3ndorph1n/CVE-2021-427560★ · 2023-02-23