FG-IR-26-123: Out-of-bounds access in CAPWAP daemon
An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-123?
FG-IR-26-123 is classified as a critical severity vulnerability due to its potential to allow remote code execution.
How do I fix FG-IR-26-123?
To fix FG-IR-26-123, you should upgrade FortiOS to version 7.6.4 or later, 7.4.9 or later, or 7.2.12 or later, depending on your current version.
Who is affected by FG-IR-26-123?
Devices operating FortiOS versions between 7.6.0 and 7.6.3, 7.4.0 and 7.4.8, and 7.2.0 and 7.2.11 are affected by FG-IR-26-123.
What type of vulnerability is FG-IR-26-123?
FG-IR-26-123 is an Out-Of-Bounds Write vulnerability, specifically classified under CWE-787.
What can an attacker achieve by exploiting FG-IR-26-123?
An attacker exploiting FG-IR-26-123 can gain execution privileges on the FortiGate device, potentially leading to full system compromise.