VYPR
Medium severity6.4NVD Advisory· Published Aug 4, 2021· Updated Jun 17, 2026

CVE-2021-26096

CVE-2021-26096

Description

Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments.

Affected products

3
  • cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: <=3.1.4
    • (no CPE)range: <4.0.0
    • (no CPE)range: FortiSandbox before 4.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.