First published: Mon Jul 12 2021(Updated: )
A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiMail | >=6.2.0<=6.2.6 | |
Fortinet FortiMail | >=6.4.0<6.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26090 is a vulnerability found in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 that allows an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.
The severity of CVE-2021-26090 is high.
CVE-2021-26090 affects FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6.
An unauthenticated remote attacker can exploit CVE-2021-26090 by sending specifically crafted login requests to the Webmail of FortiMail.
Yes, it is recommended to update FortiMail to version 6.4.5 or above to fix CVE-2021-26090.