CVE-2021-32586: Input Validation
An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32586?
CVE-2021-32586 is an improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1.
What is the severity of CVE-2021-32586?
The severity of CVE-2021-32586 is critical with a severity score of 9.8.
How does CVE-2021-32586 affect FortiMail?
CVE-2021-32586 affects FortiMail versions 5.4.12, 6.0.0 to 6.0.12, 6.2.0 to 6.2.8, 6.4.0 to 6.4.6, and 7.0.0.
What is the impact of CVE-2021-32586?
CVE-2021-32586 allows an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.
How can I fix CVE-2021-32586?
To fix CVE-2021-32586, users should upgrade FortiMail to version 7.0.1 or later.