QID 44181
Date Published: 2024-04-11
QID 44181: FortiOS Format String Vulnerability (FG-IR-23-413)
A use of externally-controlled format string vulnerability in FortiOS command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests.
Affected Versions:
FortiOS 7.4 versions 7.4.0 through 7.4.1
FortiOS 7.2 versions 7.2.0 through 7.2.7
FortiOS 7.0 all versions
FortiOS 6.4 all versions
QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable version of FortiOS may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests.
- FG-IR-23-413 -
fortiguard.fortinet.com/psirt/FG-IR-23-413
CVEs related to QID 44181
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-413 |
|