CVE-2021-36172
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.
Una vulnerabilidad de restricción inapropiada de referencias a entidades externas XML en el analizador de respuestas XML de FortiPortal versiones anteriores a 6.0.6, puede permitir a un atacante que controle el productor de informes XML consumidos por FortiPortal desencadenar una denegación de servicio o leer archivos arbitrarios del sistema de archivos subyacente mediante documentos XML específicamente diseñados
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-07-06 CVE Reserved
- 2021-11-02 CVE Published
- 2023-05-26 EPSS Updated
- 2024-10-25 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/advisory/FG-IR-21-104 | 2021-11-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 4.0.0 <= 4.0.4 Search vendor "Fortinet" for product "Fortiportal" and version " >= 4.0.0 <= 4.0.4" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 4.1.0 <= 4.1.2 Search vendor "Fortinet" for product "Fortiportal" and version " >= 4.1.0 <= 4.1.2" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 4.2.0 <= 4.2.4 Search vendor "Fortinet" for product "Fortiportal" and version " >= 4.2.0 <= 4.2.4" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 5.0.0 <= 5.0.3 Search vendor "Fortinet" for product "Fortiportal" and version " >= 5.0.0 <= 5.0.3" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 5.1.0 <= 5.1.2 Search vendor "Fortinet" for product "Fortiportal" and version " >= 5.1.0 <= 5.1.2" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 5.2.0 <= 5.2.6 Search vendor "Fortinet" for product "Fortiportal" and version " >= 5.2.0 <= 5.2.6" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 5.3.0 < 5.3.7 Search vendor "Fortinet" for product "Fortiportal" and version " >= 5.3.0 < 5.3.7" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiportal Search vendor "Fortinet" for product "Fortiportal" | >= 6.0.0 < 6.0.6 Search vendor "Fortinet" for product "Fortiportal" and version " >= 6.0.0 < 6.0.6" | - |
Affected
|