Analisi su rafaelpfister.ch

Descrizione del produttore (in inglese)

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

Dati di riferimento

Produttore
Fortinet
Prodotti interessati
  • FortiNDR
  • FortiCamera
  • FortiRecorder
  • FortiVoice
  • FortiMail
CVSS 3.1
9.6 (CRITICAL)
Vettore
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
Tipo di debolezza
CWE-121: Stack-based Buffer Overflow
Pubblicata
13 maggio 2025
Nel catalogo KEV dal
14 maggio 2025
Scadenza enti federali USA
4 giugno 2025

Fonti ufficiali

← Tutte le vulnerabilità