CVE-2021-26099: Medium severity fortinet fortimail-200d vulnerability
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphertext.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiMail issue?
The vulnerability ID for this FortiMail issue is CVE-2021-26099.
What is the severity of CVE-2021-26099?
The severity of CVE-2021-26099 is medium with a severity value of 4.9.
How does the vulnerability in FortiMail allow an attacker to compromise confidentiality?
The vulnerability in FortiMail allows an attacker who obtains the encrypted master keys to compromise their confidentiality by observing certain properties of the ciphertext.
Which versions of FortiMail are affected by this vulnerability?
Versions of FortiMail before 7.0.0 are affected by this vulnerability.
Where can I find more information about CVE-2021-26099?
You can find more information about CVE-2021-26099 on the FortiGuard Advisory page: https://fortiguard.com/advisory/FG-IR-20-244.