CVE-2021-26111 Information
Jun 07, 2022
cve
Description
A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6 6.2.0 to 6.2.6 6.0.0 to 6.0.6 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP/EDP packets to the device.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://fortiguard.com/advisory/FG-IR-21-026
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
6.5
Share on: