Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-70111
HistorySep 09, 2021 - 12:00 a.m.

Fortinet FortiWeb Buffer Overflow Vulnerability (CNVD-2021-70111)

2021-09-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
fortinet fortiweb
buffer overflow
cli interface
vulnerability
web application firewall
cross-site scripting
sql injection
cookie poisoning
schema poisoning
stack-based buffer overflow

EPSS

0.001

Percentile

41.0%

Fortinet FortiWeb is a Web application layer firewall from Fortinet that blocks threats such as cross-site scripting, SQL injection, cookie poisoning, schema poisoning and other attacks, secures Web applications and protects sensitive database content. fortiWeb suffers from a buffer overflow vulnerability. The vulnerability stems from the existence of multiple stack-based buffer overflow vulnerabilities in the FortiWeb CLI interface. This could allow an authenticated attacker to execute unauthorized code or commands via the config backup parameter. No detailed vulnerability details are available at this time.

EPSS

0.001

Percentile

41.0%

Related for CNVD-2021-70111