CVE-2024-33505: Heap buffer overflow in httpd
A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
Other sources
A heap-based buffer overflow vulnerability [CWE-122] in FortiManager and FortiAnalyzer httpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands as a low priivileged user via specifically crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33505?
The severity of CVE-2024-33505 is classified as critical due to the potential for remote code execution and escalation of privileges.
How do I fix CVE-2024-33505?
To fix CVE-2024-33505, upgrade Fortinet FortiAnalyzer and FortiManager to versions 7.4.3 or later, or 7.2.6 or later depending on your current version.
What versions are affected by CVE-2024-33505?
CVE-2024-33505 affects FortiAnalyzer versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, 7.0.0 to 7.0.12, and all 6.4.x versions.
Is FortiManager affected by CVE-2024-33505?
Yes, FortiManager versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, 7.0.0 to 7.0.12, and all 6.4.x versions are affected.
Does CVE-2024-33505 impact FortiAnalyzer Cloud?
Yes, FortiAnalyzer Cloud versions 7.4.1 to 7.4.2 and 7.2.1 to 7.2.6 are impacted by CVE-2024-33505.