A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-20-234 |
![]() ![]() |
History
Mon, 24 Mar 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests. | |
Weaknesses | CWE-358 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published: 2025-03-24T15:27:56.111Z
Updated: 2025-03-24T15:27:56.111Z
Reserved: 2021-01-25T14:47:15.095Z
Link: CVE-2021-26105

No data.

Status : Received
Published: 2025-03-24T16:15:16.610
Modified: 2025-03-24T16:15:16.610
Link: CVE-2021-26105

No data.