CVE-2021-26109: Integer Overflow
An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26109?
CVE-2021-26109 has a critical severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2021-26109?
To mitigate CVE-2021-26109, upgrade your FortiOS to version 7.0.1 or later.
Who is affected by CVE-2021-26109?
CVE-2021-26109 affects multiple versions of FortiOS prior to 7.0.1, specifically versions from 6.0.0 to 6.0.12, 6.2.0 to 6.2.9, and 6.4.0 to 6.4.5.
What type of vulnerability is CVE-2021-26109?
CVE-2021-26109 is classified as an integer overflow or wraparound vulnerability.
Can CVE-2021-26109 be exploited remotely?
Yes, CVE-2021-26109 can be exploited by unauthenticated attackers through specially crafted requests to SSLVPN.