CVE-2021-24020: Critical severity fortinet fortimail-200d vulnerability
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending further data which allows bypass of signature verification.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiMail vulnerability?
The vulnerability ID for this FortiMail vulnerability is CVE-2021-24020.
What is the severity of CVE-2021-24020?
The severity of CVE-2021-24020 is critical with a severity value of 9.8.
Which versions of FortiMail are affected by CVE-2021-24020?
FortiMail versions 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 are affected by CVE-2021-24020.
What is the impact of CVE-2021-24020?
CVE-2021-24020 may allow an unauthenticated attacker to tamper with signed URLs by appending further data, which allows bypass of signature verification.
Is there a fix for CVE-2021-24020?
There is currently no fix available for CVE-2021-24020. It is recommended to follow the mitigation steps provided by Fortinet.