CVE-2021-42756
9.8
CRITICAL · CVSS 3.1 · EPSS 35% (pctl 98)
Patch early
EPSS 35% — above the 10% action threshold.
Description
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 34.98% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-121 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-02-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| fortinet | fortiweb |
→ the Explorer · watch your stack · NVD