First published: Mon Jul 12 2021(Updated: )
An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiMail | >=5.4.0<=5.4.12 | |
Fortinet FortiMail | >=6.0.0<6.0.11 | |
Fortinet FortiMail | >=6.2.0<6.2.7 | |
Fortinet FortiMail | >=6.4.0<6.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24015 is a vulnerability in the administrative interface of FortiMail before 6.4.4, which allows an authenticated attacker to execute unauthorized commands.
CVE-2021-24015 affects FortiMail versions 5.4.0 to 5.4.12, 6.0.0 to 6.0.11, 6.2.0 to 6.2.7, and 6.4.0 to 6.4.4.
CVE-2021-24015 has a severity score of 8.8 (high).
An authenticated attacker can exploit CVE-2021-24015 by sending specifically crafted HTTP requests to the administrative interface of FortiMail.
Yes, upgrading to FortiMail version 6.4.4 or later resolves CVE-2021-24015.