CVE-2021-42756 describes multiple stack-based buffer overflow vulnerabilities in the proxy daemon of FortiWeb versions 5.x, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, and all 6.4 versions. This critical vulnerability (CVSS 9.8) allows an unauthenticated remote attacker to achieve arbitrary code execution through specially crafted HTTP requests. While not currently listed in KEV, its high EPSS score and significant community discussion (12 mentions) indicate a high potential for exploitation. There are no public exploits available in Metasploit, Nuclei, or ExploitDB, but media coverage confirms Fortinet has released patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.6.0, < 6.0.8CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.1.0, < 6.1.3CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.2.0, < 6.2.7CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.17CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.2CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.