AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-42761

CRITICAL · CVSS 9 EPSS 1.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-02-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-42761
Severity
CRITICAL
CVSS
9
EPSS
1.47%

Original NVD Description

A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to infer the session identifier of other users and possibly usurp their session.