VYPR
Medium severity4.3NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026

CVE-2021-43074

CVE-2021-43074

Description

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions; FortiSwitch 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions; FortiProxy 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.

Affected products

12
  • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.0.0,<2.0.8
    • (no CPE)range: 7.0.1 and below, 2.0.7 and below, 1.2 all versions, 1.1 all versions, 1.0 all versions
    • (no CPE)range: 7.0.0
  • Fortinet/Fortiweb3 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.0.0,<6.3.17
    • (no CPE)range: all versions
    • (no CPE)range: 6.4.0
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.0.0,<6.4.9
    • (no CPE)range: 7.0.3 and below, 6.4.8 and below, 6.2 all versions, 6.0 all versions
    • (no CPE)range: 7.0.0
  • cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*range: >=6.0.0,<6.4.11
    • (no CPE)range: 7.0.3 and below, 6.4.10 and below, 6.2 all versions, 6.0 all versions
    • (no CPE)range: 7.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.