CVE-2021-42757
—CVSS 3.1
6.7 medium
EPSS
<1%p40
Published
()
Modified
Description
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
- Vendors
- fortinet
- Products
- fortiadc, fortianalyzer, fortimail, fortimanager, fortindr, fortios-6k7k, fortiportal, fortiproxy, fortivoice, fortiweb, fortios, fortirecorder firmware
- Weakness
- CWE-120, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.