CVE-2021-26095: High severity fortinet fortimail-200d vulnerability
Published Jul 20, 2021
·Updated
The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.
Affected Software
2 affected components
Fortinet FortiMail>=6.2.0<=6.2.6
Fortinet FortiMail>=6.4.0<6.4.5
Event History
Jul 20, 2021
CVE Published
via MITRE·10:48 AM
Data Sourced
via MITRE·10:48 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-26095.
2
What is the severity level of CVE-2021-26095?
The severity level of CVE-2021-26095 is high.
3
Which versions of FortiMail are affected by CVE-2021-26095?
FortiMail versions 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 are affected by CVE-2021-26095.
4
What is the risk associated with CVE-2021-26095?
CVE-2021-26095 may allow a remote attacker to reveal, alter, or forge the session cookie.
5
Is there a fix available for CVE-2021-26095?
Fortinet has released patches to address the vulnerabilities. It is recommended to update to the latest version of FortiMail.