← Back

CVE-2021-26095

nvd nist
Published: Jul 20, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.

Affected (2)

Products: Fortinet: Fortimail
1 product
Fortimail
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.2.0 to 6.2.6
From 6.4.0 to 6.4.5

References (2)

Source: psirt@fortinet.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.