A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the recovery of the plaintexts possible.
2021-07-09T19:15:08.253
2024-11-21T05:55:52.050
Modified
CVSSv3.1: 5.9 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9