CVE-2024-33505Heap-based Buffer Overflow in Fortinet Fortianalyzer

Severity
7.3HIGHNVD
CNA5.6
EPSS
0.3%
top 49.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages5 packages

NVDfortinet/fortimanager6.0.07.2.7+1
NVDfortinet/fortianalyzer6.4.07.2.6+1
NVDfortinet/fortimanager_cloud6.4.17.2.7+1
CVEListV5fortinet/fortimanager7.4.07.4.2+5
CVEListV5fortinet/fortianalyzer7.4.07.4.2+3

🔴Vulnerability Details

2
GHSA
GHSA-pgmr-p79v-f7mc: A heap-based buffer overflow in Fortinet FortiAnalyzer version 72024-11-12
CVEList
CVE-2024-33505: A heap-based buffer overflow in Fortinet FortiAnalyzer version 72024-11-12

📋Vendor Advisories

1
Fortinet
Heap buffer overflow in httpd2024-11-12
CVE-2024-33505 — Heap-based Buffer Overflow in Fortinet | cvebase