Home/CVEs/CVE-2021-44168/

CVE-2021-44168 - Fortinet FortiOS Arbitrary File Download

Project:Fortinet

Product:FortiOS

Date Added:2021-12-10Due Date:2021-12-24

Vulnerability Name

Fortinet FortiOS Arbitrary File Download

Description

Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2021-44168