Heap-Based Buffer Overflow in FortiSandbox Command Shell
CVE-2021-26096

6.4MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
4 August 2021

Summary

The vulnerability involves multiple instances of heap-based buffer overflow found in the command shell of FortiSandbox prior to version 4.0.0. An authenticated attacker could exploit this weakness by using specially crafted command line arguments, which may lead to memory manipulation and undesired alterations of its content. As a result, the integrity of the system could be compromised, emphasizing the importance of timely updates and security measures.

Affected Version(s)

Fortinet FortiSandbox FortiSandbox before 4.0.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.