peter bassill · operator
$ cve CVE-2021-42756 JSON

CVE-2021-42756

9.8
CRITICAL · CVSS 3.1 · EPSS 35% (pctl 98)

Patch early

EPSS 35% — above the 10% action threshold.

Description

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS34.98% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-121
On CISA KEVno
Public exploitnone known
Published2023-02-16
Last modified2026-06-17

Affected (1)

VendorProduct
fortinetfortiweb

References

→ the Explorer  ·  watch your stack  ·  NVD