CVE-2021-42757: Buffer overflow in TFTP client library of CLI
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
Other sources
A buffer overflow [CWE-121] in the TFTP client library of FortiOS, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiOS buffer overflow vulnerability?
The vulnerability ID for this FortiOS buffer overflow is CVE-2021-42757.
What is the severity level of CVE-2021-42757?
The severity level of CVE-2021-42757 is medium with a CVSS score of 6.7.
Which software versions are affected by CVE-2021-42757?
CVE-2021-42757 affects FortiOS versions before 6.4.7 and FortiOS 7.0.0 through 7.0.2.
How can an attacker exploit CVE-2021-42757?
An authenticated local attacker can exploit CVE-2021-42757 by using specially crafted command line arguments to achieve arbitrary code execution.
Is there a fix available for CVE-2021-42757?
Yes, a fix is available for CVE-2021-42757 in FortiOS versions 6.4.7 and 7.0.3.