Análisis en rafaelpfister.ch

Descripción del fabricante (en inglés)

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

Datos de referencia

Fabricante
Fortinet
Productos afectados
  • FortiNDR
  • FortiCamera
  • FortiRecorder
  • FortiVoice
  • FortiMail
CVSS 3.1
9.6 (CRITICAL)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
Tipo de debilidad
CWE-121: Stack-based Buffer Overflow
Publicada
13 de mayo de 2025
En el catálogo KEV desde
14 de mayo de 2025
Plazo agencias federales de EE. UU.
4 de junio de 2025

Fuentes oficiales

← Todas las vulnerabilidades