CVE-2021-26108: High severity fortios vulnerability
A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26108?
CVE-2021-26108 is rated as a critical severity vulnerability due to the risk of the hard-coded cryptographic key being exploited.
How do I fix CVE-2021-26108?
To fix CVE-2021-26108, update FortiOS to version 7.0.1 or later, as it addresses this vulnerability.
Which versions of FortiOS are affected by CVE-2021-26108?
FortiOS versions prior to 7.0.1, specifically 5.6.0 to 5.6.13, 6.0.0 to 6.0.12, 6.2.0 to 6.2.8, and 6.4.0 to 6.4.5 are affected by CVE-2021-26108.
What is the potential impact of CVE-2021-26108?
The potential impact of CVE-2021-26108 includes unauthorized access to sensitive information due to the retrieval of the hard-coded cryptographic key.
Who is impacted by CVE-2021-26108?
Organizations using affected versions of FortiOS for SSLVPN services are impacted by CVE-2021-26108.