You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
jheysel-r7
changed the title
Add module for CVE-2024-21762 FortiOS SSLVPN out-of-bounds write to RCE
Add module for CVE-2024-21762 FortiOS out-of-bounds write to RCE
Feb 12, 2024
Seconded, this may be a poor fix to a prior cve in the same stack and may be ripe terrain to find more. Infra for the sslvpn interfaces would be great and probably useful again down the line (as well as to backfill prior exploits).
Small note of caution: the automatic updates for the fixed versions seem to be broken for a lot of users so this ones very much still out in the wild and may be for some time if the broken versions preclude auto-update (as opposed to some server side issue).
Summary
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
Basic example
PoC
Motivation
The application is widely used and is currently being exploited
The text was updated successfully, but these errors were encountered: