Vulnerability Description
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphertext.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortimail | >= 5.0, < 7.0.0 |
References
- https://fortiguard.com/advisory/FG-IR-20-244Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-20-244Vendor Advisory
FAQ
What is CVE-2021-26099?
CVE-2021-26099 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidenti...
How severe is CVE-2021-26099?
CVE-2021-26099 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26099?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortimail.