Description
A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.
Related CPE's
a
fortinet
fortimail
2
References
https://fortiguard.com/advisory/FG-IR-21-042
Vendor Advisory
https://fortiguard.com/advisory/FG-IR-21-042
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-07-12T11:15:07.827Z
4 years agoLast modified
2024-11-21T04:55:51.150Z
1 year ago