{"api_version":"1","generated_at":"2026-07-23T14:13:17+00:00","cve":"CVE-2021-42756","urls":{"html":"https://cve.report/CVE-2021-42756","api":"https://cve.report/api/cve/CVE-2021-42756.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-42756","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-42756"},"summary":{"title":"CVE-2021-42756","description":"Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2023-02-16 19:15:00","updated_at":"2023-11-07 03:39:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://fortiguard.com/psirt/FG-IR-21-186","name":"https://fortiguard.com/psirt/FG-IR-21-186","refsource":"MISC","tags":[],"title":"PSIRT Advisories | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-42756","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42756","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"42756","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiweb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"42756","vulnerable":"1","versionEndIncluding":"6.4.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiweb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-42756","qid":"730730","title":"Fortinet - FortiNAC and FortiWeb Multiple Vulnerabilities"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2021-42756","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Execute unauthorized code or commands","cweId":"CWE-121"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"FortiWeb","version":{"version_data":[{"version_affected":"<=","version_name":"6.4.0","version_value":"6.4.1"},{"version_affected":"<=","version_name":"6.3.0","version_value":"6.3.16"},{"version_affected":"<=","version_name":"6.2.0","version_value":"6.2.6"},{"version_affected":"<=","version_name":"6.1.0","version_value":"6.1.2"},{"version_affected":"<=","version_name":"6.0.0","version_value":"6.0.7"},{"version_affected":"<=","version_name":"5.9.0","version_value":"5.9.1"},{"version_affected":"<=","version_name":"5.8.5","version_value":"5.8.7"},{"version_affected":"<=","version_name":"5.8.0","version_value":"5.8.3"},{"version_affected":"<=","version_name":"5.7.0","version_value":"5.7.3"},{"version_affected":"<=","version_name":"5.6.0","version_value":"5.6.2"}]}}]}}]}},"references":{"reference_data":[{"url":"https://fortiguard.com/psirt/FG-IR-21-186","refsource":"MISC","name":"https://fortiguard.com/psirt/FG-IR-21-186"}]},"solution":[{"lang":"en","value":"Upgrade to FortiWeb 7.0.0 or above,\r\nUpgrade to FortiWeb 6.3.17 or above,\r\nUpgrade to FortiWeb 6.2.7 or above.\r\nUpgrade to FortiWeb 6.1.3 or above.\r\nUpgrade to FortiWeb 6.0.8 or above."}],"impact":{"cvss":[{"version":"3.1","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.3,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C"}]}},"nvd":{"publishedDate":"2023-02-16 19:15:00","lastModifiedDate":"2023-11-07 03:39:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3.0","versionEndExcluding":"6.3.17","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.0","versionEndExcluding":"6.2.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4.0","versionEndIncluding":"6.4.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.0","versionEndExcluding":"6.1.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6.0","versionEndExcluding":"6.0.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"42756","Ordinal":"219263","Title":"CVE-2021-42756","CVE":"CVE-2021-42756","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"42756","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}