8.8

CVE-2021-36173

A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.

Data is provided by the National Vulnerability Database (NVD)
FortinetFortios Version >= 6.0.0 <= 6.0.13
   FortinetFortigate-1100e Version-
   FortinetFortigate-200f Version-
   FortinetFortigate-2600f Version-
   FortinetFortigate-3500f Version-
   FortinetFortigate-400e Version-
   FortinetFortigate-600e Version-
   FortinetFortigate 1800f Version-
   FortinetFortigate 2200e Version-
   FortinetFortigate 3300e Version-
   FortinetFortigate 3600e Version-
   FortinetFortigate 40f Version-
   FortinetFortigate 60f Version-
   FortinetFortigate 7121f Version-
FortinetFortios Version >= 6.2.0 <= 6.2.9
   FortinetFortigate-1100e Version-
   FortinetFortigate-200f Version-
   FortinetFortigate-2600f Version-
   FortinetFortigate-3500f Version-
   FortinetFortigate-400e Version-
   FortinetFortigate-600e Version-
   FortinetFortigate 1800f Version-
   FortinetFortigate 2200e Version-
   FortinetFortigate 3300e Version-
   FortinetFortigate 3600e Version-
   FortinetFortigate 40f Version-
   FortinetFortigate 60f Version-
   FortinetFortigate 7121f Version-
FortinetFortios Version >= 6.4.0 <= 6.4.6
   FortinetFortigate-1100e Version-
   FortinetFortigate-200f Version-
   FortinetFortigate-2600f Version-
   FortinetFortigate-3500f Version-
   FortinetFortigate-400e Version-
   FortinetFortigate-600e Version-
   FortinetFortigate 1800f Version-
   FortinetFortigate 2200e Version-
   FortinetFortigate 3300e Version-
   FortinetFortigate 3600e Version-
   FortinetFortigate 40f Version-
   FortinetFortigate 60f Version-
   FortinetFortigate 7121f Version-
FortinetFortios Version7.0.0
   FortinetFortigate-1100e Version-
   FortinetFortigate-200f Version-
   FortinetFortigate-2600f Version-
   FortinetFortigate-3500f Version-
   FortinetFortigate-400e Version-
   FortinetFortigate-600e Version-
   FortinetFortigate 1800f Version-
   FortinetFortigate 2200e Version-
   FortinetFortigate 3300e Version-
   FortinetFortigate 3600e Version-
   FortinetFortigate 40f Version-
   FortinetFortigate 60f Version-
   FortinetFortigate 7121f Version-
FortinetFortios Version7.0.1
   FortinetFortigate-1100e Version-
   FortinetFortigate-200f Version-
   FortinetFortigate-2600f Version-
   FortinetFortigate-3500f Version-
   FortinetFortigate-400e Version-
   FortinetFortigate-600e Version-
   FortinetFortigate 1800f Version-
   FortinetFortigate 2200e Version-
   FortinetFortigate 3300e Version-
   FortinetFortigate 3600e Version-
   FortinetFortigate 40f Version-
   FortinetFortigate 60f Version-
   FortinetFortigate 7121f Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.4% 0.602
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
psirt@fortinet.com 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.