Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
2016-08-24T16:30:00.137
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fortinet | fortios | < 4.1.11 | Yes |
Operating System | fortinet | fortios | < 4.2.13 | Yes |
Operating System | fortinet | fortios | < 4.3.9 | Yes |
Operating System | fortinet | fortiswitch | ≤ 3.4.2 | Yes |