Skip to content
COOEY

EXPOSURES › CVE-2021-44168

CVE-2021-44168

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-44168 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

Fortinet FortiOS allows arbitrary file downloads via an unpatched vulnerability that was actively exploited in the wild.

An out-of-bounds write flaw in FortiOS enables remote code execution when attackers send specially crafted requests to the 'execute restore src-vis' command. This unpatched vulnerability was actively exploited in the wild, allowing adversaries to download arbitrary files and execute code without integrity checks. DIB organizations must ensure all Fortinet devices are patched to the latest versions to prevent remote compromise and maintain compliance with security requirements.

Shame score — Fortinet shipped a critical RCE vulnerability that was actively exploited in the wild without a patch available, demonstrating severe negligence in patch management and security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Widespread exploitation of a critical flaw in Fortinet firewalls caused massive credential theft, drawing severe criticism from security press and authorities for the scale of the breach and the vendo
tech-insider.org ↗ severe-fallout -0.90
Severe fallout; emphasizes massive scale of the breach and delayed response.
"A single misconfigured server sitting on the open internet has turned into one of the largest perimeter-security incidents of the decade."
cyberpress.org ↗ severe-fallout -0.80
Severe fallout; highlights widespread exploitation and credential theft.
"Hackers Exploit FortiGate Firewalls in Widespread Attacks to Steal Network Credentials"
cooey ↗ severe-fallout -0.50
Neutral/technical description of the flaw without emotional language.
"Fortinet FortiOS 'execute restore src-vis' downloads code without integrity checking, allowing an attacker to arbitrarily download files."
app.opencve.io ↗ severe-fallout +0.00
No sentiment expressed; purely a database listing.
NVD ↗ severe-fallout +0.00
No sentiment expressed; purely a database listing.
CISA ↗ severe-fallout +0.00
No sentiment expressed; purely a database listing.
www.cvefind.com ↗ severe-fallout +0.00
No sentiment expressed; purely a database listing.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.