CVE-2024-21762
Fortinet FortiOS Out-of-Bound Write Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
8Exploited in Wild
YesDecision
Descriptions
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
Una escritura fuera de los límites en Fortinet FortiOS versiones 7.4.0 a 7.4.2, 7.2.0 a 7.2.6, 7.0.0 a 7.0.13, 6.4.0 a 6.4.14, 6.2.0 a 6.2.15 , 6.0.0 a 6.0.17, y versiones de FortiProxy 7.4.0 a 7.4.2, 7.2.0 a 7.2.8, 7.0.0 a 7.0.14, 2.0.0 a 2.0.13, 1.2.0 a 1.2.13 , 1.1.0 a 1.1.6, 1.0.0 a 1.0.7. Permite al atacante ejecutar código o comandos no autorizados a través de solicitudes específicamente manipuladas
Fortinet FortiOS suffers from an out of bounds write vulnerability. Affected includes Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, and 1.0.0 through 1.0.7.
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2024-01-02 CVE Reserved
- 2024-02-09 CVE Published
- 2024-02-09 Exploited in Wild
- 2024-02-16 KEV Due Date
- 2024-03-14 First Exploit
- 2024-08-01 CVE Updated
- 2025-02-15 EPSS Updated
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (9)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/177602 | 2024-03-14 | |
https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check | 2024-03-24 | |
https://github.com/d0rb/CVE-2024-21762 | 2024-03-17 | |
https://github.com/h4x0r-dz/CVE-2024-21762 | 2024-03-16 | |
https://github.com/cleverg0d/CVE-2024-21762-Checker | 2024-03-25 | |
https://github.com/BishopFox/cve-2024-21762-check | 2024-11-20 | |
https://github.com/rdoix/cve-2024-21762-checker | 2024-06-20 | |
https://github.com/XiaomingX/cve-2024-21762-poc | 2024-12-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/psirt/FG-IR-24-015 | 2024-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | >= 1.0.0 < 2.0.14 Search vendor "Fortinet" for product "Fortiproxy" and version " >= 1.0.0 < 2.0.14" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | >= 7.0.0 < 7.0.15 Search vendor "Fortinet" for product "Fortiproxy" and version " >= 7.0.0 < 7.0.15" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | >= 7.2.0 < 7.2.9 Search vendor "Fortinet" for product "Fortiproxy" and version " >= 7.2.0 < 7.2.9" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | >= 7.4.0 < 7.4.3 Search vendor "Fortinet" for product "Fortiproxy" and version " >= 7.4.0 < 7.4.3" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 6.0.0 < 6.2.16 Search vendor "Fortinet" for product "Fortios" and version " >= 6.0.0 < 6.2.16" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 6.4.0 < 6.4.15 Search vendor "Fortinet" for product "Fortios" and version " >= 6.4.0 < 6.4.15" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 7.0.0 < 7.0.14 Search vendor "Fortinet" for product "Fortios" and version " >= 7.0.0 < 7.0.14" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 7.2.0 < 7.2.7 Search vendor "Fortinet" for product "Fortios" and version " >= 7.2.0 < 7.2.7" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 7.4.0 < 7.4.3 Search vendor "Fortinet" for product "Fortios" and version " >= 7.4.0 < 7.4.3" | - |
Affected
|