CVE-2021-44170
published 2022-07-18CVE-2021-44170: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an…
PriorityP430medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.20%
9.8th percentile
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortios | — | — |
| fortinet | fortios | 6.0.0 – 6.0.14 | — |
| fortinet | fortios | >= 6.2.0 < 6.2.11 | 6.2.11 |
| fortinet | fortios | >= 6.4.0 < 6.4.9 | 6.4.9 |
| fortinet | fortios | 7.0.0 – 7.0.2 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | 1.0.0 – 1.0.7 | — |
| fortinet | fortiproxy | 1.1.0 – 1.1.6 | — |
| fortinet | fortiproxy | 1.2.0 – 1.2.13 | — |
| fortinet | fortiproxy | >= 2.0.0 < 2.0.8 | 2.0.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h85f-qmh7-qh6m: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7
ghsa_unreviewed·2022-07-19
CVE-2021-44170 [MEDIUM] CWE-787 GHSA-h85f-qmh7-qh6m: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
Fortinet
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiP...
vendor_fortinet·2022-07-18·CVSS 6.7
CVE-2021-44170 [MEDIUM] CWE-787 A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiP...
FG-IR-21-179: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiP...
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
CVEs: CVE-2021-44170
CWEs: CWE-787
CVSS: 6.7 (medium)
Affected products: FortiOS, FortiProxy
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-18
Published