FG-IR-26-092: Format string vulnerability in fazsvcd
A use of externally-controlled format string vulnerability [CWE-134] in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud fazsvcd daemon may allow a remote privileged attacker with admin profile to execute arbitrary code or commands via specially crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-092?
The FG-IR-26-092 vulnerability is considered critical due to its potential to allow remote execution of arbitrary code.
How do I fix FG-IR-26-092?
To remediate FG-IR-26-092, upgrade to FortiAnalyzer or FortiManager version 7.6.5 or later, or 7.4.8 or later for earlier versions.
What products are affected by FG-IR-26-092?
FG-IR-26-092 affects FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud versions prior to the specified remedial versions.
Can FG-IR-26-092 lead to data breaches?
Yes, FG-IR-26-092 can potentially facilitate unauthorized access and lead to data breaches if exploited.
Is any user action required to exploit FG-IR-26-092?
Exploitation of FG-IR-26-092 requires a remote privileged attacker with an admin profile to launch the attack.