CVE-2021-22129: [FG-IR-21-023] Multiple buffer overflows in FortiMail
Multiple instances of incorrect calculation of buffer size in FortiMail webmail and administrative interface and FortiNDR administrative interface may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.
Other sources
Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-22129.
What is the severity of CVE-2021-22129?
CVE-2021-22129 has a severity score of 8.8, which is considered high.
How does CVE-2021-22129 affect FortiMail?
CVE-2021-22129 affects FortiMail versions up to 6.4.5.
What is the risk of CVE-2021-22129?
CVE-2021-22129 may allow an authenticated attacker to trigger a buffer overflow and execute unauthorized code or commands.
Is there a fix available for CVE-2021-22129?
Yes, FortiMail version 6.4.5 includes a fix for CVE-2021-22129. It is recommended to update to this version.