PT-2022-10087 · Fortinet · Fortimail

Published

2022-03-01

·

Updated

2022-03-09

·

CVE-2021-32586

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiMail versions prior to 7.0.1
Description The issue is related to improper input validation in the web server CGI facilities, which may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.
Recommendations For FortiMail versions prior to 7.0.1, update to version 7.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the web server CGI facilities to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32586

Affected Products

Fortimail