Medium severity6.4NVD Advisory· Published Aug 4, 2021· Updated Jun 17, 2026
CVE-2021-26096
CVE-2021-26096
Description
Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments.
Affected products
3cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: <=3.1.4
- (no CPE)range: <4.0.0
- (no CPE)range: FortiSandbox before 4.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-188nvdVendor Advisory
News mentions
0No linked articles in our index yet.