Vulnerability record · CVE-2021-22123 · published 1 June 2021
CVE-2021-22123: FortiWeb management interface OS command injection via SAML config
Fortinet · Fortiweb
FortiWeb's management interface contains an OS command injection flaw (CWE-78) reachable through the SAML server configuration page. It affects versions 6.3.7 and below, 6.2.3 and below, and the 6.1.x, 6.0.x and 5.9.x branches. Because the injected commands run on the appliance itself, a successful attack undermines the device's role as a security control.
Description
An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote authenticated command injection with high confidentiality, integrity and availability impact, plus a very high EPSS score, warrants prompt patching despite no KEV listing.
What it is
FortiWeb's management interface contains an OS command injection flaw (CWE-78) reachable through the SAML server configuration page. It affects versions 6.3.7 and below, 6.2.3 and below, and the 6.1.x, 6.0.x and 5.9.x branches. Because the injected commands run on the appliance itself, a successful attack undermines the device's role as a security control.
Impact
An attacker with valid management credentials can execute arbitrary operating system commands on the FortiWeb appliance, gaining full control of the device and any data or credentials it handles.
Attack surface
Reached over the network through the FortiWeb management interface, specifically the SAML server configuration page. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates a remote attacker who is authenticated with low privileges and requires no user interaction.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is very high at 0.7727 (99.5th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Upgrade FortiWeb to a fixed release per FortiGuard advisory FG-IR-20-120; versions 6.3.7, 6.2.3, 6.1.x, 6.0.x and 5.9.x are affected.
- Restrict management interface access to trusted administrative networks and disable it on internet-facing interfaces.
- Enforce least privilege and strong authentication for management accounts, and remove unused accounts.
- Monitor and alert on unexpected child processes or shell activity spawned by the web management service.
Detection
- Audit SAML server configuration changes in FortiWeb logs and alert on unexpected modifications.
- Monitor appliance process trees for shell or command interpreters spawned by the management web service.
- Review management interface access logs for anomalous source IPs or unusual request patterns to SAML configuration endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/advisory/FG-IR-20-120 | Vendor Advisory |
| https://fortiguard.com/advisory/FG-IR-20-120 | Vendor Advisory |
Track CVE-2021-22123 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.