Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests
Published Jul 9, 2021
9.8
CRITICALCVSS 3.1
EPSS 1.43%
Description
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected products
-
- Version FortiMail before 6.4.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Fortinet | Fortinet FortiMail | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Oct 23, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.43% (0.01430) | 72.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.43% (0.01430) | 69.44th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.17% (0.01170) | 76.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.25% (0.02247) | 74.23th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.56% (0.00559) | 66.28th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.72% (0.00717) | 81.19th | v3 (v2023.03.01) |
| May 17, 2024 | 0.72% (0.00717) | 80.47th | v3 (v2023.03.01) |
| Mar 24, 2024 | 0.68% (0.00677) | 79.44th | v3 (v2023.03.01) |
| Feb 13, 2024 | 0.49% (0.00493) | 75.47th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.38% (0.00375) | 71.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.38% (0.00375) | 68.46th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.84% (0.01840) | 47.83th | v5 (v2026.06.15) |
| Jan 6, 2022 | 1.84% (0.01840) | 47.32th | v1 |
| Sep 1, 2021 | 0.42% (0.00416) | 25.53th | v1 |
| Jul 10, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (1)
- https://fortiguard.com/advisory/FG-IR-21-012 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://fortiguard.com/advisory/FG-IR-21-012 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.