SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-42757

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

MEDIUM 6.7EPSS 0.48%

Does this matter?

Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.

Description

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.48% probability · 40th percentile
CISA KEV
Not listed
Weakness
CWE-120, CWE-787
Affected
fortinet/fortiadc · fortinet/fortianalyzer · fortinet/fortimail · fortinet/fortimanager · fortinet/fortindr · fortinet/fortios-6k7k · fortinet/fortiportal · fortinet/fortiproxy · fortinet/fortivoice · fortinet/fortiweb · fortinet/fortios · fortinet/fortirecorder firmware · fortinet/fortiswitch
Source
psirt@fortinet.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.