FG-IR-21-173: Buffer overflow in TFTP client library of CLI
A buffer overflow [CWE-121] in the TFTP client library of FortiOS, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability description of FG-IR-21-173?
FG-IR-21-173 is a buffer overflow vulnerability in the TFTP client library of FortiOS that could allow authenticated local attackers to execute arbitrary code via specially crafted command line arguments.
What are the affected products by FG-IR-21-173?
FG-IR-21-173 affects several Fortinet products including FortiADC, FortiAnalyzer, FortiDDoS, FortiMail, FortiManager, FortiNDR, FortiOS and others across various versions.
What is the severity of FG-IR-21-173?
FG-IR-21-173 is considered a critical vulnerability due to the potential for arbitrary code execution by authenticated local attackers.
How do I fix FG-IR-21-173?
To fix FG-IR-21-173, update the affected Fortinet products to the recommended versions listed in Fortinet's advisory.
Can FG-IR-21-173 be exploited remotely?
No, FG-IR-21-173 can only be exploited by authenticated local attackers, not remotely.