CVE-2021-43074

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1and below, 2.0.7and below, 1.2 all versions, 1.1 all versions, 1.0 all versionsmay allow an attackerto decrypt portions of the administrative session management cookieif able to intercept the latter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
fortinetCNA
4.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:C
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
VendorProductVersion
fortinetfortiproxy
1.0.0 ≤
𝑥
< 2.0.8
fortinetfortiproxy
7.0.0 ≤
𝑥
< 7.0.2
fortinetfortiweb
6.0.0 ≤
𝑥
< 6.3.17
fortinetfortiweb
6.4.0 ≤
𝑥
< 7.0.0
fortinetfortios
6.0.0 ≤
𝑥
< 6.4.9
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.4
fortinetfortiswitch
6.0.0 ≤
𝑥
< 6.4.11
fortinetfortiswitch
7.0.0 ≤
𝑥
< 7.0.4
𝑥
= Vulnerable software versions