CVE-2021-36173 HIGH

CVE-2021-36173

Vendor Fortinet
Product Fortinet FortiOS
Published December 8, 2021
Last update October 25, 2024

CVSS base score

8.0/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C

What the vulnerability does

01Description

A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.

Key dates

02Disclosure timeline

December 8, 2021 CVE published
October 25, 2024 Record updated