VYPR
Medium severity5.4NVD Advisory· Published Mar 2, 2022· Updated Jun 17, 2026

CVE-2021-43070

CVE-2021-43070

Description

Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

Affected products

4
  • Range: <=8.6.2, <=8.5.2, <=8.4.2, <=8.3.3, <=8.2.2
  • Fortinet/Fortinetcpe-rescue
    Range: FortiWLM 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2
  • Fortinet/Fortiwlm2 versions
    cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:*range: >=8.3.0,<=8.3.3
    • cpe:2.3:a:fortinet:fortiwlm:8.2.2:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.