QID 44043
Date Published: 2023-05-31
QID 44043: FortiOS Stack-Based Buffer Overflow Vulnerability (FG-IR-21-179) (Unauthenticated check)
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS and FortiProxy may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
Affected Products:
FortiOS version 6.0.0 through 6.0.14
FortiOS version 6.2.0 through 6.2.10
FortiOS version 6.4.0 through 6.4.8
FortiOS version 7.0.0 through 7.0.2
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable FortiOS may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-179
Vendor References
- FG-IR-21-179 -
www.fortiguard.com/psirt/FG-IR-21-179
CVEs related to QID 44043
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-179 |
|