CVE-2024-35279: Stack buffer overflow in fabric service
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack protections and provided the fabric service is running on the exposed interface.
Other sources
A stack-based buffer overflow [CWE-121] vulnerability in FortiOS CAPWAP control may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets, provided the attacker were able to evade FortiOS stack protections and provided the fabric service is running on the exposed interface.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35279?
CVE-2024-35279 is classified as a critical vulnerability due to its potential to allow remote unauthenticated attackers to execute arbitrary code.
How do I fix CVE-2024-35279?
To fix CVE-2024-35279, upgrade Fortinet FortiOS to versions 7.2.9 or 7.4.5 or later.
What kind of attack does CVE-2024-35279 enable?
CVE-2024-35279 enables remote attackers to exploit a stack-based buffer overflow by sending crafted UDP packets.
Which versions of FortiOS are affected by CVE-2024-35279?
FortiOS versions 7.2.4 through 7.2.8 and 7.4.0 through 7.4.4 are affected by CVE-2024-35279.
Who can exploit CVE-2024-35279?
CVE-2024-35279 can be exploited by remote unauthenticated attackers.