CVE-2021-41014

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
08/12/2021
Last modified:
09/12/2021

Description

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.7 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.5 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 6.3.0 (including) 6.3.15 (including)
cpe:2.3:a:fortinet:fortiweb:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools