← Back to CVE List
Vulnerability Intelligence Report
Fortinet FortiOS Arbitrary File Download

CVE-2021-44168

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
3.3
LOW
Exploitability:1.9
Impact Score:1.5
Temporal Score:3.2
EPSS Probability:0.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-494 ↗CWE-494 Download of Code Without Integrity Check

Affected Products & Versions

Vendor Product Affected Versions
Fortinet Fortinet FortiOS FortiOS before 7.0.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
0.865%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityFortinet, Inc. · Vendor · USA
Reserved2021-11-23T00:00:00
Published2022-01-04T12:38:04
Last Updated2025-10-21T23:15:50

LINK COPIED TO CLIPBOARD