Lucene search

K
cveFortinetCVE-2021-41029
HistoryDec 08, 2021 - 12:15 p.m.

CVE-2021-41029

2021-12-0812:15:07
CWE-79
fortinet
web.nvd.nist.gov
24
6
cve-2021-41029
fortinet
fortiwlm
web security
cross-site scripting
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:P/RC:C

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

29.4%

A improper neutralization of input during web page generation (‘cross-site scripting’) in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests

Affected configurations

Nvd
Node
fortinetfortiwlmRange8.6.1
VendorProductVersionCPE
fortinetfortiwlm*cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Fortinet FortiWLM",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiWLM 8.6.1, 8.6.0, 8.5.2, 8.5.1, 8.5.0, 8.4.2, 8.4.1, 8.4.0, 8.3.2, 8.3.1, 8.3.0, 8.2.2"
      }
    ]
  }
]

Social References

More

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:P/RC:C

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

29.4%

Related for CVE-2021-41029