FG-IR-26-098: Buffer overflow via fgtupdates service
A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiManager fgtupdates service may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-098?
The FG-IR-26-098 vulnerability is classified as a high severity stack-based buffer overflow issue.
How do I fix FG-IR-26-098?
To fix FG-IR-26-098, update FortiManager to version 7.4.3 or 7.2.11, depending on your current version.
Which products are affected by FG-IR-26-098?
FG-IR-26-098 affects FortiManager versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.10, and all 6.4 versions.
Can FG-IR-26-098 be exploited remotely?
Yes, FG-IR-26-098 can be exploited remotely by an unauthenticated attacker if the fgtupdates service is enabled.
What type of vulnerability is FG-IR-26-098?
FG-IR-26-098 is a stack-based buffer overflow vulnerability as defined by CWE-121.