Memory Exhaustion Vulnerability in FortiSwitch by Fortinet
CVE-2021-26111
6.5MEDIUM
What is CVE-2021-26111?
FortiSwitch devices from version 3.6.11 and lower to 6.4.6 are vulnerable to a memory exhaustion issue due to a missing release of memory after the effective lifetime. An attacker located on an adjacent network can exploit this vulnerability by sending specially crafted LLDP, CDP, or EDP packets to the affected device, potentially exhausting the available memory and impacting device performance.
Affected Version(s)
Fortinet FortiSwitch FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below