HIGH

CVE-2021-44168

Fortinet Fortios 2022-01-04 CVSS v3.1
CVSS
7.8
KEV

Description

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

Summary dbcve.org

This is a local authenticated vulnerability in FortiOS where the 'execute restore src-vis' command does not perform integrity verification on update packages before downloading. An authenticated local attacker can exploit the lack of code signing/validation to download arbitrary files from the device filesystem via specially crafted malicious update packages.

Mitigation

Upgrade FortiOS to version 7.0.3 or later which implements integrity checking for restore packages. If immediate upgrade is not possible, restrict administrative access to trusted local users only and monitor for suspicious restore command usage.

Weakness (CWE)

CWE-494

EPSS Score

0.87%
Probability of exploitation in next 30 days
57.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE