CVE-2021-24015: OS Command Injection
An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24015?
CVE-2021-24015 is a vulnerability in the administrative interface of FortiMail before 6.4.4, which allows an authenticated attacker to execute unauthorized commands.
How does CVE-2021-24015 affect FortiMail?
CVE-2021-24015 affects FortiMail versions 5.4.0 to 5.4.12, 6.0.0 to 6.0.11, 6.2.0 to 6.2.7, and 6.4.0 to 6.4.4.
What is the severity of CVE-2021-24015?
CVE-2021-24015 has a severity score of 8.8 (high).
How can an attacker exploit CVE-2021-24015?
An authenticated attacker can exploit CVE-2021-24015 by sending specifically crafted HTTP requests to the administrative interface of FortiMail.
Is there a fix for CVE-2021-24015?
Yes, upgrading to FortiMail version 6.4.4 or later resolves CVE-2021-24015.