QID 43945

Date Published: 2022-12-19

QID 43945: FortiOS - Unauthorized Command Execution Vulnerability (FG-IR-22-419)

An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Affected Versions:
FortiOS version 7.2.1
FortiOS version 7.2.2

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation of the vulnerability may allow remote code execution.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-398
    Vendor References

    CVEs related to QID 43945

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-419 URL Logo www.fortiguard.com/psirt/FG-IR-22-419