A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.2.6Upgrade FortiAnalyzer to 7.2.4Upgrade FortiAnalyzer to 7.4.2Upgrade to the latest version of FortiAnalyzerUpgrade FortiAnalyzer to 7.0.10 | Mar 25, 2024 | Mar 12, 2024 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.0.10Upgrade FortiManager to 7.4.2Upgrade to the latest version of FortiManagerUpgrade FortiManager to 7.2.4 | Apr 29, 2024 | Mar 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub