FG-IR-23-415: Buffer overflow in administrative interface
Published May 14, 2024
·Updated
A stack-based buffer overflow [CWE-121] vulnerability in FortiOS administrative interface may allow a privileged attacker to execute arbitrary code or commands via crafted HTTP or HTTPs requests.
Affected Software
2 affected componentsFixes available
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.1<=7.2.7
Event History
May 14, 2024
Advisory Published
via FortiGuard·12:00 AM
Jan 15, 2025
Advisory Published
via FortiGuard·10:47 AM
Frequently Asked Questions
1
What is the severity of FG-IR-23-415?
The severity of FG-IR-23-415 is critical due to the potential for arbitrary code execution by a privileged attacker.
2
How do I fix FG-IR-23-415?
To fix FG-IR-23-415, upgrade FortiOS to version 7.4.2 or 7.2.8 or later.
3
Which versions of FortiOS are affected by FG-IR-23-415?
FortiOS versions 7.4.0 to 7.4.1 and 7.2.1 to 7.2.7 are affected by FG-IR-23-415.
4
Can FG-IR-23-415 be exploited remotely?
Yes, FG-IR-23-415 can be exploited remotely through crafted HTTP or HTTPS requests.
5
Who is impacted by FG-IR-23-415?
Any organization using the affected versions of FortiOS is at risk of FG-IR-23-415.