A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the `diagnose system geoip-city` command with a large ip value.
2021-07-20T11:15:11.410
2024-11-21T05:52:13.657
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortianalyzer | < 6.2.8 | Yes |
Application | fortinet | fortianalyzer | < 6.4.6 | Yes |
Application | fortinet | fortimanager | < 6.2.8 | Yes |
Application | fortinet | fortimanager | < 6.4.6 | Yes |