A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to version 6.2.10Upgrade FortiAnalyzer to 7.0.3Upgrade FortiAnalyzer to 6.4.8Upgrade FortiAnalyzer to 6.0.12 | Dec 13, 2021 | Dec 8, 2021 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 6.4.8Upgrade FortiManager to version 6.2.10Upgrade FortiManager to 6.0.12Upgrade FortiManager to version 7.0.3 | Mar 14, 2022 | Dec 8, 2021 |
| Fortinet Fortiproxy | — | Upgrade to the latest version of FortiProxyUpgrade FortiProxy to 2.0.8Upgrade FortiProxy to 7.0.2 | Sep 30, 2026 | Dec 7, 2021 |
| Fortios | — | Upgrade to the latest version of FortiOS | Dec 13, 2021 | Dec 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub