CVE-2021-41014

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
fortinetCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:C
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
fortinetfortiweb
6.0.0 ≤
𝑥
≤ 6.0.7
fortinetfortiweb
6.2.0 ≤
𝑥
≤ 6.2.5
fortinetfortiweb
6.3.0 ≤
𝑥
≤ 6.3.15
fortinetfortiweb
6.1.0
fortinetfortiweb
6.1.1
fortinetfortiweb
6.1.2
fortinetfortiweb
6.4.0
fortinetfortiweb
6.4.1
𝑥
= Vulnerable software versions