Vulnerability Description
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and directory deletion in the device filesystem.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiweb | >= 5.8.0, < 6.3.16 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-21-158Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-21-158Vendor Advisory
FAQ
What is CVE-2021-42753?
CVE-2021-42753 is a vulnerability with a CVSS score of 8.1 (HIGH). An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x ...
How severe is CVE-2021-42753?
CVE-2021-42753 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42753?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiweb.