CVE-2021-44168lowunder attackCWE-494

CVE-2021-44168: low-severity vulnerability in Fortinet FortiOS

Published · Updated

58Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 3.3epss 0.9%
from disclosure to weapon400 days
Published on NVDJan 4
1st PoC+400d
CISA KEVDec 10
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2021-12-24

Apply updates per vendor instructions.

In short

A vulnerability in FortiOS allows a local authenticated user to download arbitrary files to the device when using the restore command, because the system doesn't verify if the downloaded files are legitimate before using them.

Technical detail

CWE-494 (Download of Code Without Integrity Check) in FortiOS <7.0.3 'execute restore src-vis' command allows local authenticated attackers to download and execute arbitrary files by crafting malicious update packages; requires local access and valid credentials; impacts file integrity and potential code execution on the device.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:U/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.