A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fortinet
Subscribe
|
Fortigate-1100e
Subscribe
Fortigate-200f
Subscribe
Fortigate-2600f
Subscribe
Fortigate-3500f
Subscribe
Fortigate-400e
Subscribe
Fortigate-600e
Subscribe
Fortigate 1800f
Subscribe
Fortigate 2200e
Subscribe
Fortigate 3300e
Subscribe
Fortigate 3600e
Subscribe
Fortigate 40f
Subscribe
Fortigate 60f
Subscribe
Fortigate 7121f
Subscribe
Fortios
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-22794 | A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.com/advisory/FG-IR-21-115 |
|
History
Fri, 25 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-25T13:38:38.298Z
Reserved: 2021-07-06T00:00:00
Link: CVE-2021-36173
Updated: 2024-08-04T00:47:43.827Z
Status : Modified
Published: 2021-12-08T19:15:09.787
Modified: 2024-11-21T06:13:15.267
Link: CVE-2021-36173
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD