Aller au contenu

Fiche vulnérabilité

CVE-2021-36173 : faille élevée Fortinet Fortinet FortiOS (CVSS 8.0)

Description

A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.

En bref

Sévérité
Élevée (CVSS 8.0)
Vecteur CVSS
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
Exploitation active
Non signalée par la CISA
Publication
8 déc. 2021
Dernière mise à jour
25 oct. 2024

Produits concernés

  • Fortinet Fortinet FortiOS

Références

Rechercher une autre vulnérabilité dans la base CVE