Inadequate encryption strength in FortiMail - CVE-2021-26095
Published: July 13, 2021
FortiMail
Fortinet, Inc
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to a combination of various cryptographic issues in the session management of FortiMail, including the encryption construction of the session cookie. A remote user with possession of a valid session cookie can decrypt it and reveal or alter its content.
Successful exploitation of the vulnerability may allow an attacker to escalate privileges on the system.