Lucene search

K
fortinetFortiGuard LabsFG-IR-21-027
HistoryJul 07, 2021 - 12:00 a.m.

FortiMail - Salted Digest vulnerable to length extension attacks

2021-07-0700:00:00
FortiGuard Labs
www.fortiguard.com
16
fortimail
hash digest
vulnerability
cryptographic step
signed urls
bypass signature verification
implementation
length extension attack
software

EPSS

0.003

Percentile

70.0%

A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail may allow an unauthenticated attacker to tamper with signed URLs by appending further data which allows bypass of signature verification.

EPSS

0.003

Percentile

70.0%

Related for FG-IR-21-027