CVE-2021-26095

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/07/2021
Last modified:
08/08/2023

Description

The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.6 (including)
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.5 (excluding)


References to Advisories, Solutions, and Tools