TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-44168

LOWCISA KEV
3.3

Description

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

Details CVE

Score CVSS v3.13.3
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie1/4/2022
Derniere modification10/24/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurFortinet
ProduitFortiOS
Nom vulnerabiliteFortinet FortiOS Arbitrary File Download
Date ajout KEV2021-12-10
Date limite remediation2021-12-24
Utilise dans ransomwareUnknown

Produits affectes

fortinet:fortios

Faiblesses (CWE)

CWE-494CWE-494

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.