« Volver al listado

CVE-2021-41014

Estado: ModificadaAlta (7.5)—

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-41014",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-41014",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-23T14:16:04.138306Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@fortinet.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@fortinet.com",
      "affectedData": [
        {
          "vendor": "Fortinet",
          "product": "Fortinet FortiWeb",
          "versions": [
            {
              "status": "affected",
              "version": "FortiWeb 6.4.1, 6.4.0, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.2, 6.3.1, 6.3.0, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.1.2, 6.1.1, 6.1.0, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-08T13:15:07.847",
  "references": [
    {
      "url": "https://fortiguard.com/advisory/FG-IR-21-131",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@fortinet.com"
    },
    {
      "url": "https://fortiguard.com/advisory/FG-IR-21-131",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets"
    },
    {
      "lang": "es",
      "value": "Un consumo no controlado de recursos en Fortinet FortiWeb versiones 6.4.1 y anteriores, 6.3.15 y anteriores, permite a un atacante no autenticado hacer que el demonio httpsd no responda por medio de enormes paquetes HTTP"
    }
  ],
  "lastModified": "2026-06-17T04:07:44.713",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5931460-A0F1-4BED-ADEF-A48602EA747C",
              "versionEndIncluding": "6.0.7",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60265BD0-4C66-43FF-898B-9433B4D4B0F5",
              "versionEndIncluding": "6.2.5",
              "versionStartIncluding": "6.2.0"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F59449EE-C44E-4EE7-80DC-5194A9B5B4CD",
              "versionEndIncluding": "6.3.15",
              "versionStartIncluding": "6.3.0"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:6.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96B929BB-7B7A-40D2-AB13-D4FDD41FD159"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:6.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A3C5370-3453-4F07-B551-7E36F815578C"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:6.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "415AF153-2A59-488B-A78B-D98B7F39B5AF"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74A92A08-E6F6-4522-A6DA-061950AD3525"
            },
            {
              "criteria": "cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6A3D2C4-C3FA-4E12-9156-DAFEA4E00BCC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@fortinet.com"
}