Security readout for executives and security teams
Plain-English summary
This flaw can let an unauthenticated attacker on an adjacent network crash Fortinet's DHCP daemon on affected products. The expected impact is denial of service, not data theft or takeover, but DHCP disruption can affect network availability.
Executive priority
Handle as a moderate availability issue. It is not described as remote takeover, but DHCP outages can disrupt business connectivity, especially in branch, campus, or voice environments using affected Fortinet platforms.
Technical view
CVE-2021-42755 is a CWE-190 integer overflow or wraparound in the dhcpd daemon across listed Fortinet FortiSwitch, FortiRecorder, FortiOS, FortiProxy, and FortiVoiceEnterprise versions. CVSS 3.1 is 4.3: adjacent attack vector, low complexity, no privileges, no user interaction, availability impact only.
Likely exposure
Exposure is most likely where affected Fortinet appliances run vulnerable versions and their DHCP service is reachable from adjacent network segments. The provided data does not identify internet-routable exploitation.
Exploitation context
The bundle marks CISA KEV as false. The CVSS vector includes E:F, but no provided source confirms active exploitation, weaponization, or observed attacks. Treat this as a plausible adjacent-network denial-of-service risk.
Researcher notes
Evidence is limited to the CVE record and Fortinet PSIRT reference. The affected range is broad across several product families. Validation should focus on version confirmation, DHCP role, and adjacent-network reachability rather than internet exposure assumptions.
Mitigation direction
- Review Fortinet PSIRT FG-IR-21-155 for fixed versions and upgrade guidance.
- Prioritize affected systems providing DHCP for critical network segments.
- Restrict DHCP exposure to trusted network segments where operationally possible.
- Monitor Fortinet advisories for updated remediation or workaround instructions.
Validation and detection
- Inventory FortiSwitch, FortiRecorder, FortiOS, FortiProxy, and FortiVoiceEnterprise versions.
- Compare installed versions against the affected ranges in CVE-2021-42755.
- Confirm which devices run DHCP services on reachable interfaces.
- Check logs and monitoring for unexpected dhcpd restarts or availability drops.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-42755 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 4.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:F/RL:U/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:F/RL:U/RC:C2.81.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
4.3MediumVector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:F/RL:U/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- https://fortiguard.com/psirt/FG-IR-21-155CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
