CVE-2021-26090

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/07/2021
Last modified:
13/07/2021

Description

A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.6 (including)
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.5 (excluding)


References to Advisories, Solutions, and Tools