CVE-2021-26105: Buffer Overflow
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26105?
CVE-2021-26105 is classified as a critical vulnerability due to the potential for unauthorized code execution.
How do I fix CVE-2021-26105?
To fix CVE-2021-26105, upgrade FortiSandbox to version 3.2.3 or later, or version 3.1.5 or later.
Who is affected by CVE-2021-26105?
Any user running FortiSandbox version 3.2.2 or lower, or version 3.1.4 or lower is affected by CVE-2021-26105.
What kind of attacks can be executed due to CVE-2021-26105?
An attacker can execute arbitrary code or commands through specially crafted HTTP requests due to CVE-2021-26105.
Is authentication required to exploit CVE-2021-26105?
Yes, an attacker must be authenticated to exploit CVE-2021-26105.