First published: Tue Dec 12 2023(Updated: )
A format string vulnerability [CWE-134] in the HTTPSd daemon of FortiOS, FortiProxy and FortiPAM may allow an authenticated user to execute unauthorized code or commands via specially crafted API requests.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | =. | |
Fortinet FortiOS | >=7.2.0<=7.2.4 | |
Fortinet FortiOS | >=7.0.0<=7.0.11 | |
Fortinet FortiOS | >=6.4.0<=6.4.12 | |
Fortinet FortiOS | >=6.2.0<=6.2.15 | |
Fortinet FortiOS | >=6.0 | |
Fortinet FortiPAM | =. | |
Fortinet FortiPAM | >=1.0 | |
Fortinet FortiProxy | >=7.2.0<=7.2.4 | |
Fortinet FortiProxy | >=7.0.0<=7.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.