A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiproxy | — | Upgrade FortiProxy to 7.4.7Upgrade FortiProxy to 7.2.13Upgrade to the latest version of FortiProxyUpgrade FortiProxy to 7.6.1Upgrade FortiProxy to 7.0.20 | Sep 30, 2026 | Mar 11, 2025 |
| Fortinet Fortiweb | — | Upgrade FortiWeb to 7.6.1Upgrade FortiWeb to 7.0.11Upgrade FortiWeb to 7.4.6Upgrade FortiWeb to 7.2.11 | Jun 30, 2026 | Mar 11, 2025 |
| Fortios | — | Upgrade FortiOS to 7.2.10Upgrade FortiOS to 7.0.16Upgrade FortiOS to 6.4.16Upgrade FortiOS to 7.4.5Upgrade FortiOS to 6.2.17 | Mar 12, 2025 | Mar 11, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub