CVE-2021-26105
24.03.2025, 16:15
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortisandbox | 3.1.0 ≤ 𝑥 ≤ 3.1.4 |
| fortinet | fortisandbox | 3.2.0 ≤ 𝑥 < 3.2.3 |
| fortinet | fortisandbox | 4.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-358 - Improperly Implemented Security Check for StandardThe software does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.