CVE-2024-21762

KEV
🔴 Łataj teraz

Przepełnienie bufora w FortiOS umożliwia zdalne wykonanie nieautoryzowanego kodu.

CVSS
9.8
EPSS
84.3%
Exploit
weaponized
Vendor
fortinet
Opis źródłowy (NVD)

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)84.3%
Opublikowano (NVD)2024-02-09 09:15:08 UTC
Ostatnia modyfikacja (NVD)2026-08-04 05:16:30 UTC
Referencje