CVE-2021-42757

MEDIUM

Fortinet Fortiadc < 6.1.5 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0007
EPSS Percentile 21.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120 CWE-787
Status published
Products (19)
fortinet/fortiadc 5.0.0 - 6.1.5
fortinet/fortianalyzer 6.0.0 - 6.4.7
fortinet/fortimail 5.4.0 - 6.2.7
fortinet/fortimanager 6.0.0 - 6.4.7
fortinet/fortindr 1.1.0 - 1.5.2
fortinet/fortios 5.0.0 - 6.0.13
fortinet/fortios-6k7k 6.4.2
fortinet/fortios-6k7k 6.4.6
fortinet/fortios-6k7k < 6.2.8
fortinet/fortiportal 5.0.0 - 6.0.10
... and 9 more
Published Dec 08, 2021
Tracked Since Feb 18, 2026