FG-IR-25-084: Heap-based buffer overflow in cw_acd daemon
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiSwitchManager cwacd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.The presence of security controls such as ASLR and PIE considerably raises the complexity and preparation effort required for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-084?
The severity of FG-IR-25-084 is critical as it allows remote unauthenticated attackers to execute arbitrary code.
How do I fix FG-IR-25-084?
To fix FG-IR-25-084, update FortiOS or FortiSwitchManager to the recommended versions or later as specified in the advisory.
What products are affected by FG-IR-25-084?
FG-IR-25-084 affects multiple versions of FortiOS and FortiSwitchManager among other Fortinet products.
Can FG-IR-25-084 be exploited remotely?
Yes, FG-IR-25-084 can be exploited remotely without authentication through specially crafted requests.
What type of vulnerability is FG-IR-25-084?
FG-IR-25-084 is a heap-based buffer overflow vulnerability categorized under CWE-122.