CVE-2021-44170: Buffer Overflow
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44170?
CVE-2021-44170 is a stack-based buffer overflow vulnerability in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8.
What is the severity of CVE-2021-44170?
The severity of CVE-2021-44170 is medium, with a severity value of 6.7.
How can an attacker exploit CVE-2021-44170?
An authenticated attacker can exploit CVE-2021-44170 by executing unauthorized code or commands via specially crafted command line arguments.
Which software versions are affected by CVE-2021-44170?
FortiOS versions before 7.0.4 and FortiProxy versions before 2.0.8 are affected by CVE-2021-44170.
Is there a fix available for CVE-2021-44170?
Yes, it is recommended to update to FortiOS 7.0.4 or later and FortiProxy 2.0.8 or later to fix CVE-2021-44170.