FG-IR-23-356: Stack buffer overflow on bluetooth write feature
Published Jun 11, 2024
·Updated
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in FortiOS may allow an authenticated attacker to achieve arbitrary code execution via specially crafted CLI commands.
Affected Software
6 affected componentsFixes available
Fortinet FortiOS>=7.4.0<=7.4.3
Fortinet FortiOS>=7.2.0<=7.2.7
Fortinet FortiOS>=7.0.0<=7.0.15
Fortinet FortiOS>=6.4
Fortinet FortiOS>=6.2
Fortinet FortiOS>=6.0
Event History
Jun 11, 2024
Advisory Published
via FortiGuard·12:00 AM
Dec 2, 2024
Advisory Published
via FortiGuard·01:30 PM
Frequently Asked Questions
1
What is the severity of FG-IR-23-356?
The severity of FG-IR-23-356 is critical due to the potential for arbitrary code execution.
2
How do I fix FG-IR-23-356?
To fix FG-IR-23-356, update FortiOS to version 7.4.4, 7.2.8, or 7.0.16 or higher.
3
What types of attacks are possible due to FG-IR-23-356?
FG-IR-23-356 may allow authenticated attackers to execute arbitrary code via specially crafted CLI commands.
4
Which versions of FortiOS are affected by FG-IR-23-356?
FortiOS versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.7, and 7.0.0 to 7.0.15 are specifically affected by FG-IR-23-356.
5
Can FG-IR-23-356 be exploited remotely?
FG-IR-23-356 requires authentication, meaning an attacker needs valid credentials to exploit the vulnerability.