6.5

CVE-2021-36190

A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortiweb Version >= 6.0.0 <= 6.0.7
Fortinet ≫ Fortiweb Version >= 6.2.0 <= 6.2.6
Fortinet ≫ Fortiweb Version >= 6.3.0 <= 6.3.15
Fortinet ≫ Fortiweb Version 6.1.0
Fortinet ≫ Fortiweb Version 6.1.1
Fortinet ≫ Fortiweb Version 6.1.2
Fortinet ≫ Fortiweb Version 6.4.0
Fortinet ≫ Fortiweb Version 6.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.52
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Fortinet 5.5 2.1 3.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://fortiguard.com/advisory/FG-IR-21-123
Patch
Vendor Advisory