CVE-2021-44168 is a critical vulnerability affecting Fortinet FortiOS versions prior to 7.0.3, stemming from a lack of integrity checks during code downloads initiated by the "execute restore src-vis" command. This flaw allows a local, authenticated attacker to download arbitrary files onto the device using specially crafted update packages. With a CVSS score of 7.8 (HIGH), this vulnerability poses a significant risk due to its low attack complexity and high potential for confidentiality, integrity, and availability impacts. Notably, this CVE is listed in CISA's KEV catalog, indicating active exploitation in the wild, despite a lack of public exploit code in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.14CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.2.0, < 6.2.10CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.4.0, < 6.4.8CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.3CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.