First published: Fri Jul 09 2021(Updated: )
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the recovery of the plaintexts possible.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiMail | <7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26100.
The severity of CVE-2021-26100 is high with a value of 7.5.
The affected software of CVE-2021-26100 is Fortinet FortiMail before version 7.0.0.
CVE-2021-26100 allows an unauthenticated attacker to manipulate encrypted messages intercepted in the Identity-Based Encryption service of FortiMail, potentially enabling tampering and recovery of plaintexts.
Yes, a fix is available for CVE-2021-26100. Please refer to the advisory link provided for more information.