CVE-2021-36173: Heap-based Buffer Overflow in firmware signature verification
A heap-based buffer overflow [CWE-122] in the firmware signature verification function of FortiOS may allow an attacker to execute arbitrary code via specially crafted installation images.
Other sources
A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36173?
CVE-2021-36173 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2021-36173?
To fix CVE-2021-36173, upgrade FortiOS to a version that is not vulnerable, specifically versions later than those listed in the advisory.
Which versions of FortiOS are affected by CVE-2021-36173?
CVE-2021-36173 affects FortiOS versions from 6.0.0 to 6.0.13, 6.2.0 to 6.2.9, 6.4.0 to 6.4.6, and 7.0.0 to 7.0.1.
What type of vulnerability is CVE-2021-36173?
CVE-2021-36173 is a heap-based buffer overflow that occurs in the firmware signature verification function.
Can CVE-2021-36173 be exploited remotely?
Yes, CVE-2021-36173 can be exploited remotely if an attacker provides specially crafted installation images.