FG-IR-24-325: Multiple format string vulnerabilities
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS, FortiProxy, FortiPAM, FortiSRA and FortiWeb may allow a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-325?
The severity of FG-IR-24-325 is critical due to the potential for unauthorized code execution.
How do I fix FG-IR-24-325?
To mitigate FG-IR-24-325, update to the recommended versions of affected products as specified by Fortinet.
Which products are affected by FG-IR-24-325?
FG-IR-24-325 affects FortiOS, FortiProxy, FortiPAM, FortiSRA, and FortiWeb versions prior to their respective remedies.
Who can exploit FG-IR-24-325?
FG-IR-24-325 can be exploited by a privileged attacker through specially crafted HTTP or HTTPS commands.
What kind of vulnerability is FG-IR-24-325?
FG-IR-24-325 is defined as a use of externally-controlled format string vulnerability, classified as CWE-134.