CVE-2021-22123
43Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.6epss 77%
exploitation probability
77%top 1% of all CVEs
observed exploitation
nono source reports it
In short
A vulnerability in FortiWeb's management interface allows authenticated users to inject and run arbitrary system commands through the SAML server configuration page. This could let an attacker take complete control of the affected system.
Technical detail
OS command injection vulnerability in FortiWeb management interface (versions 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x) accessible via SAML server configuration page. Attack requires prior authentication and allows execution of arbitrary OS commands with system privileges, leading to complete system compromise.
Summary generated and translated by AI from the official description.
An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Affected products
Fortinet · Fortinet FortiWeb