CVE-2021-24013
CVE-2021-24013 is a high-severity vulnerability in Fortinet Fortimail with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- CVSS v2: 4.0
- EPSS exploit prediction: 1% (65th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Fortinet Fortimail
- Published:
- Last modified:
Description
Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.
Frequently asked questions
- What is CVE-2021-24013?
- Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.
- How severe is CVE-2021-24013?
- CVE-2021-24013 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2021-24013 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (65th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-24013?
- CVE-2021-24013 affects Fortinet Fortimail. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-24013?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2021-24013 published?
- CVE-2021-24013 was published on 2021-07-12 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*
More vulnerabilities in Fortinet Fortimail
- CVE-2026-104286 — Critical (CVSS 9.8): An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail…
- CVE-2025-32756 — Critical (CVSS 9.8): A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3,…
- CVE-2023-47539 — Critical (CVSS 9.8): An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and…
- CVE-2021-36166 — Critical (CVSS 9.8): An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one…
- CVE-2021-24007 — Critical (CVSS 9.8): Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may…
- CVE-2020-9294 — Critical (CVSS 9.8): An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0…
All CVEs affecting Fortinet Fortimail →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-55393 — Critical (CVSS 10.0): Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9…
- CVE-2026-97163 — Critical (CVSS 10.0): Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1,…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9,…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.