CVE-2024-21762
KEV
🔴 Łataj teraz
Przepełnienie bufora w FortiOS umożliwia zdalne wykonanie nieautoryzowanego kodu.
CVSS
9.8
EPSS
84.3%
Exploit
weaponized
Vendor
fortinet
Opis źródłowy (NVD)
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 84.3% |
| Opublikowano (NVD) | 2024-02-09 09:15:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:30 UTC |
Referencje
- https://fortiguard.com/psirt/FG-IR-24-015 (psirt@fortinet.com) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21762 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]