QID 44041

Date Published: 2023-05-31

QID 44041: Fortinet FortiOS Buffer Overflow Vulnerability (FG-IR-21-206) (Unauthenticated check)

A buffer copy without checking size of input may allow a privileged attacker to execute arbitrary code or command via crafted CLI operations with the TFTP protocol.

Affected Products:
FortiOS version 6.0.0 through 6.0.14
FortiOS version 6.2.0 through 6.2.10
FortiOS version 6.4.0 through 6.4.8
FortiOS version 7.0.0 through 7.0.5

QID Detection Logic(UnAuthenticated):
QID checks the vulnerable version

It may allow a privileged attacker to execute unauthorized arbitrary code or commands via crafted CLI.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to refer to FG-IR-21-206 for more information.
    Vendor References

    CVEs related to QID 44041

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-206 URL Logo www.fortiguard.com/psirt/FG-IR-21-206