CVE-2021-36173

A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
fortinetfortios
6.0.0 ≤
𝑥
≤ 6.0.13
fortinetfortios
6.2.0 ≤
𝑥
≤ 6.2.9
fortinetfortios
6.4.0 ≤
𝑥
≤ 6.4.6
fortinetfortios
7.0.0
fortinetfortios
7.0.1
𝑥
= Vulnerable software versions