A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
2022-07-18T17:15:08.483
2024-11-21T06:30:29.760
Modified
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | ≤ 1.0.7 | Yes |
Application | fortinet | fortiproxy | ≤ 1.1.6 | Yes |
Application | fortinet | fortiproxy | ≤ 1.2.13 | Yes |
Application | fortinet | fortiproxy | < 2.0.8 | Yes |
Operating System | fortinet | fortios | ≤ 6.0.14 | Yes |
Operating System | fortinet | fortios | < 6.2.11 | Yes |
Operating System | fortinet | fortios | < 6.4.9 | Yes |
Operating System | fortinet | fortios | ≤ 7.0.2 | Yes |