CVE-2021-42755
4.3
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0.0, 2.0.6 and below, 1.2.x, 1.1.x, 1.0.x; FortiVoiceEnterprise 6.4.3 and below, 6.0.10 and below dhcpd daemon may allow an unauthenticated and network adjacent attacker to crash the dhcpd deamon, resulting in potential denial of service.
Affected (130)
Products: Fortinet: Fortios, Fortiproxy, Fortirecorder Firmware, Fortiswitch, Fortivoice
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.4.0 | |
| From 1.0.0 to 1.0.7 | |
| Version 6.0.0 | |
| From 6.0.0 to 6.0.7 | |
| Version 5.3.0 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.