CVE-2021-26100: High severity fortinet fortimail-200d vulnerability
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the recovery of the plaintexts possible.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-26100.
What is the severity of CVE-2021-26100?
The severity of CVE-2021-26100 is high with a value of 7.5.
What is the affected software of CVE-2021-26100?
The affected software of CVE-2021-26100 is Fortinet FortiMail before version 7.0.0.
How does CVE-2021-26100 affect the Identity-Based Encryption service of FortiMail?
CVE-2021-26100 allows an unauthenticated attacker to manipulate encrypted messages intercepted in the Identity-Based Encryption service of FortiMail, potentially enabling tampering and recovery of plaintexts.
Is there a fix available for CVE-2021-26100?
Yes, a fix is available for CVE-2021-26100. Please refer to the advisory link provided for more information.