FG-IR-24-196: Format String Bug in fazsvcd
A use of externally-controlled format string vulnerability [CWE-134] in FortiAnalyzer fazsvcd daemon may allow a remote privileged attacker with admin profile to execute arbitrary code or commands via specially crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-196?
The severity of FG-IR-24-196 is critical, as it allows remote privileged attackers to execute arbitrary code or commands.
How do I fix FG-IR-24-196?
To fix FG-IR-24-196, upgrade FortiAnalyzer or FortiAnalyzer Cloud to versions 7.4.4 or 7.2.7 or later.
Which versions are affected by FG-IR-24-196?
FG-IR-24-196 affects FortiAnalyzer versions 7.4.0 to 7.4.3 and 7.2.2 to 7.2.5, as well as corresponding FortiAnalyzer Cloud versions.
Who is impacted by FG-IR-24-196?
Organizations using vulnerable versions of FortiAnalyzer or FortiAnalyzer Cloud are impacted by FG-IR-24-196.
Is remote access required for exploits targeting FG-IR-24-196?
Yes, a remote privileged attacker must have an admin profile to exploit FG-IR-24-196.