QID 44170
Date Published: 2024-02-09
QID 44170: FortiOS Out-of-Bound Write Vulnerability in sslvpnd (FG-IR-24-015)
A out-of-bounds write vulnerability [CWE-787] in FortiOS may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests.
Affected Versions:
FortiOS 7.4 versions 7.4.0 through 7.4.2
FortiOS 7.2 versions 7.2.0 through 7.2.6
FortiOS 7.0 versions 7.0.0 through 7.0.13
FortiOS 6.4 versions 6.4.0 through 6.4.14
FortiOS 6.2 versions 6.2.0 through 6.2.15
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable version of FortiOS may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-24-015
- FG-IR-24-015 -
www.fortiguard.com/psirt/FG-IR-24-015
CVEs related to QID 44170
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-24-015 |
|