imPC@ndo IT

Tracker / CVE-2021-42757

CVE-2021-42757

Medium 6.7

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

Affected products and versions

fortinet fortiadc · 5.0.0 → 6.1.5
fortinet fortiadc · 6.2.0 → 6.2.2
fortinet fortianalyzer · 6.0.0 → 6.4.7
fortinet fortianalyzer · 7.0.0 → 7.0.2
fortinet fortimail · 5.4.0 → 6.2.7
fortinet fortimail · 6.4.0 → 6.4.6
fortinet fortimail · 7.0.0 → 7.0.2
fortinet fortimanager · 6.0.0 → 6.4.7
fortinet fortimanager · 7.0.0 → 7.0.2
fortinet fortindr · 1.1.0 → 1.5.2
fortinet fortios · 5.0.0 → 6.0.13
fortinet fortios · 6.2.0 → 6.2.9
fortinet fortios · 6.4.0 → 6.4.7
fortinet fortios · 7.0.0 → 7.0.2
fortinet fortios-6k7k
fortinet fortios-6k7k · … → 6.2.8
fortinet fortiportal · 5.0.0 → 6.0.10
fortinet fortiproxy
fortinet fortiproxy · 1.0.0 → 2.0.7
fortinet fortirecorder_firmware · 2.6.0 → 6.0.10
fortinet fortirecorder_firmware · 6.4.0 → 6.4.2
fortinet fortiswitch · 6.0.0 → 6.4.9
fortinet fortiswitch · 7.0.0 → 7.0.3
fortinet fortivoice · 6.0.0 → 6.0.10
fortinet fortivoice · 6.4.0 → 6.4.4
fortinet fortiweb
fortinet fortiweb · 5.0.0 → 6.3.16

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References