ZeroHour

CVE-2021-36190

CVSS 3.1
6.3 medium
EPSS
<1%p55
Published
()
Modified
Description

A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.

Vendors
fortinet
Products
fortiweb
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.