CVE-2024-46663
published 2025-03-11CVE-2024-46663: A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute…
PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.18%
7.2th percentile
A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimail | — | — |
| fortinet | fortimail | >= 6.4.0 < 7.2.7 | 7.2.7 |
| fortinet | fortimail | 6.4.0 – 6.4.8 | — |
| fortinet | fortimail | 7.0.0 – 7.0.8 | — |
| fortinet | fortimail | 7.2.0 – 7.2.7 | — |
| fortinet | fortimail | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortimail | 7.4.0 – 7.4.3 | — |
| fortinet | fortimail | >= 7.6.0 < 7.6.2 | 7.6.2 |
| fortinet | fortimail | 7.6.0 – 7.6.1 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-57fw-f86h-vwgm: A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7
ghsa_unreviewed·2025-03-11
CVE-2024-46663 [MEDIUM] CWE-121 GHSA-57fw-f86h-vwgm: A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7
A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.
Fortinet
A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a...
vendor_fortinet·2025-03-11·CVSS 6.7
CVE-2024-46663 [MEDIUM] CWE-121 A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a...
FG-IR-24-331: A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a...
A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.
CVEs: CVE-2024-46663
CWEs: CWE-121
CVSS: 6.7 (medium)
Affected products: FortiMail, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-11
Published