4.3
CVSSv3

CVE-2021-32598

Published: 05/08/2021 Updated: 12/08/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager and FortiAnalyzer GUI 7.0.0, 6.4.6 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow an authenticated and remote malicious user to perform an HTTP request splitting attack which gives attackers control of the remaining headers and body of the response.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortianalyzer

fortinet fortimanager