CVE-2024-23110Stack-based Buffer Overflow in Fortinet Fortios

Severity
7.8HIGHNVD
EPSS
0.2%
top 64.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11

Description

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortios6.0.06.2.16+4
CVEListV5fortinet/fortios7.4.07.4.2+5

🔴Vulnerability Details

2
CVEList
CVE-2024-23110: A stack-based buffer overflow in Fortinet FortiOS version 72024-06-11
GHSA
GHSA-4xv7-gmf4-mjpg: A stack-based buffer overflow in Fortinet FortiOS version 72024-06-11

📋Vendor Advisories

2
Fortinet
Multiple buffer overflows in diag npu command2024-06-11
Microsoft
Microsoft Defender Security Feature Bypass Vulnerability2024-03-12
CVE-2024-23110 — Stack-based Buffer Overflow | cvebase