CVE-2024-26010: Buffer overflow in fgfmd
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specially crafted packets.
Other sources
A stack-based overflow vulnerability [CWE-124] in FortiOS, FortiProxy, FortiPAM and FortiSwitchManager may allow a remote attacker to execute arbitrary code or command via crafted packets reaching the fgfmd daemon, under certain conditions which are outside the control of the attacker.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26010?
CVE-2024-26010 has a high severity rating due to its stack-based buffer overflow vulnerability.
How do I fix CVE-2024-26010?
To fix CVE-2024-26010, update affected Fortinet products to the latest versions as recommended by Fortinet.
Which Fortinet products are affected by CVE-2024-26010?
CVE-2024-26010 affects FortiPAM, FortiOS, FortiWeb, FortiAuthenticator, and FortiSwitchManager across specific versions.
Can CVE-2024-26010 be exploited remotely?
Yes, CVE-2024-26010 can potentially be exploited remotely to execute arbitrary code on affected systems.
What types of attacks can CVE-2024-26010 lead to?
CVE-2024-26010 can lead to denial-of-service attacks or unauthorized access to systems due to code execution.