CVE-2022-33871: Buffer Overflow
A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI execute backup-local rename and execute backup-local show operations.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-33871.
How severe is the CVE-2022-33871 vulnerability?
The severity of the CVE-2022-33871 vulnerability is high.
Which software versions are affected by CVE-2022-33871?
FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier are affected by CVE-2022-33871.
What is the CWE ID for CVE-2022-33871?
The CWE ID for CVE-2022-33871 is CWE-121.
How can an attacker exploit CVE-2022-33871?
A privileged attacker can execute arbitrary code or commands by exploiting the CVE-2022-33871 vulnerability through specifically crafted CLI `execute backup-local rename` and `execute backup-local show` commands.