QID 44171
Date Published: 2024-02-12
QID 44171: FortiOS Format String Vulnerability in fgfmd (FG-IR-24-029)
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Affected Versions:
FortiOS 7.4 versions 7.4.0 through 7.4.2
FortiOS 7.2 versions 7.2.0 through 7.2.6
FortiOS 7.0 versions 7.0.0 through 7.0.13
QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable version of FortiOS's fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-24-029
- FG-IR-24-029 -
www.fortiguard.com/psirt/FG-IR-24-029
CVEs related to QID 44171
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-24-029 |
|