High severity8.8NVD Advisory· Published Dec 9, 2021· Updated Jun 17, 2026
CVE-2021-36194
CVE-2021-36194
Description
Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.
Affected products
56.4.1, 6.4.0, 6.3.0 - 6.3.15+ 4 more
- (no CPE)range: 6.4.1, 6.4.0, 6.3.0 - 6.3.15
- (no CPE)range: FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15
- cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.3.0,<=6.3.15
- cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-21-152nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.