Vulnerability record · CVE-2021-44168 · published 4 January 2022
CVE-2021-44168: FortiOS restore src-vis command downloads code without integrity check
Fortinet · Fortios
FortiOS before 7.0.3 fails to verify the integrity of code downloaded by the "execute restore src-vis" command, allowing specially crafted update packages to place arbitrary files on the device. Because the flaw is in a restore/update path, it undermines the trust boundary defenders rely on when applying vendor packages.
Description
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows arbitrary file write with high impact and is listed in CISA KEV as exploited, though it requires local authenticated access and EPSS probability is low.
What it is
FortiOS before 7.0.3 fails to verify the integrity of code downloaded by the "execute restore src-vis" command, allowing specially crafted update packages to place arbitrary files on the device. Because the flaw is in a restore/update path, it undermines the trust boundary defenders rely on when applying vendor packages.
Impact
A local authenticated attacker can write arbitrary files on the device, which can lead to code execution or persistence depending on what is overwritten. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached locally through the FortiOS CLI command "execute restore src-vis" using a crafted update package. It requires an authenticated local account; no user interaction beyond issuing the command is indicated by the vector (AV:L/PR:L/UI:N).
Exploitation
CVE-2021-44168 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2021-12-10 addition date, indicating exploitation in the wild. EPSS 30-day probability is low at 0.00873 (57th percentile), and no ransomware campaign use is recorded.
What to do
- Upgrade FortiOS to 7.0.3 or later per the Fortinet advisory FG-IR-21-201.
- Restrict CLI and administrative access to trusted administrators and enforce least privilege on local accounts.
- Verify the provenance and integrity of any restore or update package before running "execute restore src-vis".
- Monitor and alert on use of restore/update commands outside approved maintenance windows.
Detection
- Audit FortiOS logs for execution of "execute restore src-vis" and correlate with change tickets.
- Alert on unexpected file creation or modification in system paths following restore operations.
- Review administrative account activity for anomalous local logins preceding restore commands.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-44168 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Fortinet FortiOS Arbitrary File Download". Required action: Apply updates per vendor instructions. Federal deadline 24 December 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/psirt/FG-IR-21-201 | Vendor Advisory |
| https://fortiguard.com/psirt/FG-IR-21-201 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44168 | US Government Resource |
Track CVE-2021-44168 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44168), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.