← Back

CVE-2021-26091

nvd nist
Published: Mar 24, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: psirt@fortinet.com (Secondary)

Description

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.

Affected (1)

Products: Fortinet: Fortimail
1 product
Fortimail
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.2.0 to 6.4.5

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.