LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-44168: Fortinet FortiOS Arbitrary File Download

RBRecent Breaches Vulnerability Intelligence·Dec 10, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 24, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-44168 to its Known Exploited Vulnerabilities catalog on Dec 10, 2021, with a federal patch deadline of Dec 24, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

CVE-2021-44168 is an arbitrary file download weakness in Fortinet FortiOS. It stems from the "execute restore src-vis" function downloading code without integrity checking, which can let an attacker cause the system to retrieve files of their choosing. For IT and security teams running FortiOS, this matters because devices that enforce network policy are high-value targets; successful abuse can undermine device integrity and open paths to further compromise. Confirm all product and version details against the vendor advisory before acting.

How it works

The underlying issue is CWE-494: download of code without integrity checking. In this case, a FortiOS administrative or restore-related command path fetches external content and does not adequately verify that the material is authentic or untampered before use. An attacker who can influence the download source or the conditions under which the command runs may cause the device to pull arbitrary files instead of expected, vendor-supplied content.

At a high level, the abuse path involves triggering or abusing the restore/src-vis style download so that the appliance retrieves attacker-controlled data. Exact preconditions, required privileges, and network reachability are not fully detailed in the public summary; treat any internet-facing or broadly reachable management plane as higher risk and validate the precise attack surface in the vendor advisory. No exploit mechanics beyond the CISA description should be assumed.

Am I affected? How to find it in your systems

FortiOS typically runs on Fortinet FortiGate firewalls and related security appliances that sit at network perimeters, in data centers, or as virtual instances. Inventory every Fortinet device under management: check hardware and virtual FortiGate fleets, HA pairs, and any management or orchestration systems that push configuration to them.

How to remediate

Patch first. Apply the FortiOS updates that Fortinet released for this issue, following the vendor’s instructions exactly. CISA’s required action is to apply updates per vendor instructions; schedule maintenance windows promptly for internet-facing and critical path devices.

If you can't patch immediately

Until the vendor update is installed, reduce exposure with compensating controls aimed at this class of integrity-check failures.

If your data may have been exposed

Actively exploited vulnerabilities on network devices can lead to broader breaches, even when ransomware use is not documented for this CVE. If you have indicators of compromise or suspect the device was abused, follow your incident-response process: isolate affected systems, preserve logs and disk images, rotate credentials and certificates that traversed the device, and assess downstream impact. As a routine hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiOS
WeaknessCWE-494
Added to CISA KEVDec 10, 2021
Federal patch deadlineDec 24, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities