CVE-2021-44168

CVE Published 2022-01-04
Related CWE(s) CWE-494: Download of Code Without Integrity Check
Related Vendor(s) fortinet
Related Product(s) fortios
Exploitation Reported (CISA KEV) 2021-12-10
CVSS 3 Base Score 3.3 (LOW)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References