← volver
CVE-2021-43074

CVE-2021-43074

CVSS 4.1 MEDIUMEPSS 0.3%CWE-347
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
16 feb 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:C

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →