VYPR
High severity7.5NVD Advisory· Published Dec 8, 2021· Updated Jun 17, 2026

CVE-2021-41014

CVE-2021-41014

Description

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets

Affected products

8
  • Fortinet/Fortiweb8 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.7
    • cpe:2.3:a:fortinet:fortiweb:6.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
    • (no CPE)range: <=6.4.1, <=6.3.15
    • (no CPE)range: FortiWeb 6.4.1, 6.4.0, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.1.2, 6.1.1, 6.1.0, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.