cbcvebase.
CVE-2024-35279
published 2025-02-11

CVE-2024-35279: A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote…

PriorityP357high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.01%
59.0th percentile
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack protections and provided the fabric service is running on the exposed interface.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios>= 7.2.4 < 7.2.97.2.9
fortinetfortios7.2.4 – 7.2.8
fortinetfortios>= 7.4.0 < 7.4.57.4.5
fortinetfortios7.4.0 – 7.4.4

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for crafted UDP packets targeting the CAPWAP control channel on FortiOS devices, which is the attack vector for this stack-based buffer overflow.
  • Verify whether the fabric service is running on internet-exposed interfaces on FortiOS 7.2.4–7.2.8 or 7.4.0–7.4.4; exposure of this service is a prerequisite for exploitation.
  • ·Exploitation requires the attacker to evade FortiOS stack protections in addition to reaching the CAPWAP/fabric service; this raises the practical bar for successful exploitation despite the high CVSS score.
  • ·Affected versions are FortiOS 7.2.4 through 7.2.8 and 7.4.0 through 7.4.4; ensure devices outside these ranges are confirmed patched or unaffected before deprioritising.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.