cbcvebase.
CVE-2024-26010
published 2024-06-11

CVE-2024-26010: A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager…

high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specially crafted packets.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortiauthenticator
fortinetfortinet
fortinetfortios
fortinetfortios>= 6.0.0 < 7.0.157.0.15
fortinetfortios6.0.0 – 6.0.18
fortinetfortios6.2.0 – 6.2.16
fortinetfortios6.4.0 – 6.4.15
fortinetfortios7.0.0 – 7.0.14
fortinetfortios>= 7.2.0 < 7.2.87.2.8
fortinetfortios7.2.0 – 7.2.7
fortinetfortios>= 7.4.0 < 7.4.47.4.4
fortinetfortios7.4.0 – 7.4.3
fortinetfortipam
fortinetfortipam
fortinetfortipam1.0.0 – 1.3.0
fortinetfortipam1.1.0 – 1.1.2
fortinetfortiproxy
fortinetfortiproxy>= 1.0.0 < 7.0.177.0.17
fortinetfortiproxy1.0.0 – 1.0.7
fortinetfortiproxy1.1.0 – 1.1.6
fortinetfortiproxy1.2.0 – 1.2.13
fortinetfortiproxy2.0.0 – 2.0.13
fortinetfortiproxy7.0.0 – 7.0.15
fortinetfortiproxy>= 7.2.0 < 7.2.107.2.10
fortinetfortiproxy7.2.0 – 7.2.9