CVE-2021-24022Classic Buffer Overflow in Fortinet Fortianalyzer

Severity
4.4MEDIUMNVD
CNA6.7
EPSS
0.1%
top 84.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 24

Description

A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the `diagnose system geoip-city` command with a large ip value.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

NVDfortinet/fortimanager6.0.06.2.8+1
NVDfortinet/fortianalyzer6.0.06.2.8+1

🔴Vulnerability Details

2
GHSA
GHSA-mm7j-58p9-3pxq: A buffer overflow vulnerability in FortiAnalyzer CLI 62022-05-24
CVEList
CVE-2021-24022: A buffer overflow vulnerability in FortiAnalyzer CLI 62021-07-20

📋Vendor Advisories

1
Fortinet
A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5...2021-07-20
CVE-2021-24022 — Classic Buffer Overflow in Fortinet | cvebase