peter bassill · operator
$ cve CVE-2021-44168 JSON

CVE-2021-44168 KEV

3.3
LOW · CVSS 3.1 · EPSS 0.9% (pctl 57)

Patch first

On CISA KEV — known exploited in the wild, due 2021-12-24.

Description

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

Scoring

CVSS3.3 (LOW, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS0.87% — more likely to be exploited than 57% of all CVEs
WeaknessCWE-494
On CISA KEVyes — remediate by 2021-12-24
Public exploitnone known
Published2022-01-04
Last modified2026-06-17

CISA KEV

NameFortinet FortiOS Arbitrary File Download
Added2021-12-10
Due2021-12-24
Vendor / productFortinet / FortiOS
Ransomware usenone reported

Affected (1)

VendorProduct
fortinetfortios

References

→ the Explorer  ·  watch your stack  ·  NVD