CVE-2021-26096: Multiple heap corruption vulnerabilities in FSA's command shell
Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments.
Other sources
Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this heap-based buffer overflow?
The vulnerability ID for this heap-based buffer overflow is CVE-2021-26096.
What is the affected software for this vulnerability?
The affected software is FortiSandbox versions up to and including 3.1.4, and versions between 3.2.0 and 3.2.3.
What is the severity of CVE-2021-26096?
The severity of CVE-2021-26096 is rated as high with a CVSS score of 8.8.
How can an attacker exploit this vulnerability?
An authenticated attacker can exploit this vulnerability by manipulating memory and altering its content through specifically crafted command line arguments.
Is there a fix or patch available for this vulnerability?
Yes, Fortinet has released FortiSandbox version 4.0.0 which addresses this vulnerability. It is recommended to upgrade to this version to fix the issue.