CVE-2024-21762
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
- Affected products
- Fortios, Fortiproxy
- Fortinet Fortiproxy
- < 2.0.14, 7.0.15, 7.2.9, 7.4.3
- Fortinet Fortios
- < 6.0.18, 6.2.16, 6.4.15, 7.0.14, 7.2.7, 7.4.3
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 84.3% (100th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2024-02-09
Fix
Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.9 or above Please upgrade to FortiProxy version 7.0.15 or above Please upgrade to FortiProxy version 2.0.14 or above Please upgrade to FortiOS version 7.6.0 or above Please upgrade to FortiOS version 7.4.3 or above Please upgrade to FortiOS version 7.2.7 or above Please upgrade to FortiOS version 7.0.14 or above Please upgrade to FortiOS version 6.4.15 or above Please upgrade to FortiOS version 6.2.16 or above
12 known exploits for CVE-2024-21762
Proof-of-concept code and exploit modules indexed by Sploitus