VYPR
Unrated severityNVD Advisory· Published Dec 8, 2021· Updated Oct 16, 2025

CVE-2021-42757

CVE-2021-42757

Description

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

Affected products

14
  • cpe:2.3:a:fortinet:fortimail:7.0.2:*:*:*:*:*:*:*
    Range: 7.0.0
  • Fortinet/FortiPortalv5
    cpe:2.3:a:fortinet:fortiportal:6.0.10:*:*:*:*:*:*:*
    Range: 6.0.0
  • Fortinet/FortiRecorderv5
    cpe:2.3:a:fortinet:fortirecorder:6.4.2:*:*:*:*:*:*:*
    Range: 6.4.0
  • Fortinet/FortiSwitchv5
    cpe:2.3:a:fortinet:fortiswitch:7.0.3:*:*:*:*:*:*:*
    Range: 7.0.0
  • cpe:2.3:a:fortinet:fortivoice:6.4.4:*:*:*:*:*:*:*
    Range: 6.4.0
  • Fortinet/FortiADCv5
    cpe:2.3:h:fortinet:fortiadc:6.2.2:*:*:*:*:*:*:*
    Range: 6.2.0
  • cpe:2.3:o:fortinet:fortianalyzer:7.0.2:*:*:*:*:*:*:*
    Range: 7.0.0
  • Fortinet/FortiDDoSv5
    cpe:2.3:o:fortinet:fortiddos:5.5.1:*:*:*:*:*:*:*
    Range: 5.5.0
  • cpe:2.3:o:fortinet:fortiddos-f:6.4.1:*:*:*:*:*:*:*
    Range: 6.4.0
  • cpe:2.3:o:fortinet:fortimanager:7.0.2:*:*:*:*:*:*:*
    Range: 7.0.0
  • cpe:2.3:o:fortinet:fortios:7.0.2:*:*:*:*:*:*:*
    Range: 7.0.0
  • Range: 6.4.0
  • Range: 1.5.0
  • Range: 7.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.