6.7

CVE-2021-42757

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FortinetFortiadc Version >= 5.0.0 <= 6.1.5
FortinetFortiadc Version >= 6.2.0 <= 6.2.2
FortinetFortianalyzer Version >= 6.0.0 <= 6.4.7
FortinetFortianalyzer Version >= 7.0.0 <= 7.0.2
FortinetFortimail Version >= 5.4.0 <= 6.2.7
FortinetFortimail Version >= 6.4.0 <= 6.4.6
FortinetFortimail Version >= 7.0.0 <= 7.0.2
FortinetFortimanager Version >= 6.0.0 <= 6.4.7
FortinetFortimanager Version >= 7.0.0 <= 7.0.2
FortinetFortiNDR Version >= 1.1.0 <= 1.5.2
FortinetFortios-6k7k Version <= 6.2.8
FortinetFortios-6k7k Version6.4.2
FortinetFortios-6k7k Version6.4.6
FortinetFortiportal Version >= 5.0.0 <= 6.0.10
FortinetFortiproxy Version >= 1.0.0 <= 2.0.7
FortinetFortiproxy Version7.0.0
FortinetFortiproxy Version7.0.1
FortinetFortivoice Version >= 6.0.0 <= 6.0.10
FortinetFortivoice Version >= 6.4.0 <= 6.4.4
FortinetFortiweb Version >= 5.0.0 <= 6.3.16
FortinetFortiweb Version6.4.0
FortinetFortiweb Version6.4.1
FortinetFortios Version >= 5.0.0 <= 6.0.13
FortinetFortios Version >= 6.2.0 <= 6.2.9
FortinetFortios Version >= 6.4.0 <= 6.4.7
FortinetFortios Version >= 7.0.0 <= 7.0.2
FortinetFortirecorder Firmware Version >= 2.6.0 <= 6.0.10
FortinetFortirecorder Firmware Version >= 6.4.0 <= 6.4.2
FortinetFortiswitch Version >= 6.0.0 <= 6.4.9
FortinetFortiswitch Version >= 7.0.0 <= 7.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.212
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@fortinet.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.