QID 44098
Date Published: 2023-08-09
QID 44098: FortiOS - Buffer Overflow Vulnerability (FG-IR-23-149)
A stack-based buffer overflow vulnerability [CWE-121] in FortiOS may allow a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.
Affected Versions:
FortiOS version 7.0.0 through 7.0.3
FortiOS 6.4 all versions
FortiOS 6.2 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable version of FortiOS may allow a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-149
- FG-IR-23-149 -
www.fortiguard.com/psirt/FG-IR-23-149
CVEs related to QID 44098
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-149 |
|