CVE-2021-44170Out-of-bounds Write in Fortinet Fortios

Severity
6.7MEDIUMNVD
EPSS
0.1%
top 68.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateJul 19

Description

A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortios6.2.06.2.11+3
NVDfortinet/fortiproxy2.0.02.0.8+3

🔴Vulnerability Details

2
GHSA
GHSA-h85f-qmh7-qh6m: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 72022-07-19
CVEList
CVE-2021-44170: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 72022-07-18

📋Vendor Advisories

1
Fortinet
A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiP...2022-07-18
CVE-2021-44170 — Out-of-bounds Write in Fortinet | cvebase