A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI `execute backup-local rename` and `execute backup-local show` operations.
2023-02-16T19:15:12.730
2024-11-21T07:08:29.840
Modified
CVSSv3.1: 6.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | < 6.3.20 | Yes |
Application | fortinet | fortiweb | 6.4.0 | Yes |
Application | fortinet | fortiweb | 6.4.1 | Yes |
Application | fortinet | fortiweb | 6.4.2 | Yes |
Application | fortinet | fortiweb | 7.0.0 | Yes |
Application | fortinet | fortiweb | 7.0.1 | Yes |