← Back

CVE-2021-26109

nvd nist
Published: Dec 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.

Affected (4)

Products: Fortinet: Fortios
1 product
Fortios
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.0.0 to 6.0.12
From 6.2.0 to 6.2.9
From 6.4.0 to 6.4.5
Version 7.0.0

References (2)

Source: psirt@fortinet.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.