PT-2022-12008 · Fortinet · Fortios+1
Published
2022-07-05
·
Updated
2022-07-25
·
CVE-2021-44170
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiOS versions prior to 7.0.4
FortiProxy versions prior to 2.0.8
Description
A stack-based buffer overflow vulnerability in the command line interpreter of FortiOS and FortiProxy may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
Recommendations
For FortiOS versions prior to 7.0.4, update to version 7.0.4 or later to resolve the issue.
For FortiProxy versions prior to 2.0.8, update to version 2.0.8 or later to resolve the issue.
As a temporary workaround, consider restricting access to the command line interpreter until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios
Fortiproxy