CVE-2024-21758
published 2025-01-14CVE-2024-21758: A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code…
PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.22%
12.3th percentile
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 7.2.0 < 7.2.8 | 7.2.8 |
| fortinet | fortiweb | 7.2.0 – 7.2.7 | — |
| fortinet | fortiweb | >= 7.4.0 < 7.4.2 | 7.4.2 |
| fortinet | fortiweb | 7.4.0 – 7.4.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri...
vendor_fortinet·2025-01-14·CVSS 6.4
CVE-2024-21758 [MEDIUM] CWE-121 A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri...
FG-IR-23-458: A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri...
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.
CVEs: CVE-2024-21758
CWEs: CWE-121
CVSS: 6.4 (medium)
Affected products: FortiWeb, Fortinet
GHSA
GHSA-5xxp-3j63-qv9w: A stack-based buffer overflow in Fortinet FortiWeb versions 7
ghsa_unreviewed·2025-01-14
CVE-2024-21758 [MEDIUM] CWE-120 GHSA-5xxp-3j63-qv9w: A stack-based buffer overflow in Fortinet FortiWeb versions 7
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-14
Published