CVE-2021-26091: Weak RNG
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26091?
CVE-2021-26091 has been classified as a high severity vulnerability due to its potential to allow unauthenticated attackers to compromise user authentication.
How do I fix CVE-2021-26091?
To fix CVE-2021-26091, update FortiMail to version 6.4.5 or later, or 6.2.8 or later to mitigate the vulnerability.
Who is affected by CVE-2021-26091?
CVE-2021-26091 affects users of FortiMail versions 6.4.0 to 6.4.4 and 6.2.0 to 6.2.7.
What are the potential impacts of CVE-2021-26091?
The potential impacts of CVE-2021-26091 include the ability for attackers to infer authentication tokens, leading to unauthorized access.
Is there a workaround for CVE-2021-26091?
There is no official workaround for CVE-2021-26091; users are advised to upgrade to the patched versions.