FG-IR-20-125: [FortiWeb] Stack-Based Buffer Overflow vulnerability using a crafted request
A stack-based buffer overflow [CWE-121] vulnerability in FortiWeb may allow an unauthenticated attacker to overwrite the content of the stack and potentially execute arbitrary code by sending crafted HTTP requests with large request parameter values.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-20-125?
The severity of FG-IR-20-125 is high due to the potential for arbitrary code execution by unauthenticated attackers.
How do I fix FG-IR-20-125?
To fix FG-IR-20-125, it is recommended to update FortiWeb to the latest version provided by Fortinet.
What type of attack does FG-IR-20-125 enable?
FG-IR-20-125 enables a stack-based buffer overflow attack that can overwrite the stack content.
Is authentication required to exploit FG-IR-20-125?
No, an attacker does not need to be authenticated to exploit FG-IR-20-125.
What can an attacker do with FG-IR-20-125?
An attacker can potentially execute arbitrary code on the affected FortiWeb device by sending crafted HTTP requests.