CVE-2021-22123 is an OS command injection vulnerability in the management interface of FortiWeb versions 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, and 5.9.x. A remote authenticated attacker can exploit this flaw via the SAML server configuration page to execute arbitrary commands on the system. This vulnerability carries a high CVSS score of 8.8, indicating a severe impact with high confidentiality, integrity, and availability compromise, and has a high EPSS score suggesting a significant likelihood of exploitation. While not currently listed in CISA's KEV catalog, there is notable community discussion and media coverage, indicating significant attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.9.0, < 6.2.4CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.8CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.