Junglewise Threat Intelligence

CVE-2021-44168: Fortinet FortiOS Arbitrary File Download

CVE-2021-44168 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-12-10

Technologies: Fortinet FortiOS. Vendors: Fortinet.

Executive brief

A download of code without integrity check vulnerability in the 'execute restore src-vis' command of Fortinet FortiOS allows a local authenticated attacker to download arbitrary files via specially crafted update packages. The vulnerability stems from a lack of proper verification for downloaded content.

Affected products

  • Fortinet FortiOS before 7.0.3

Timeline

  • 2021-12-10: disclosed: Date added to CISA KEV catalog
  • 2021-12-10: kev added
  • 2022-01-04: advisory: NVD Published Date
  • 2021-12-10: exploited

Related threats