PT-2022-2396 · Fortinet · Fortiwan
Published
2022-04-06
·
Updated
2022-04-13
·
CVE-2021-26112
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiWAN versions prior to 4.5.9
Description
The issue is related to multiple stack-based buffer overflow vulnerabilities in both network daemons and the command line interpreter. This may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code via specifically crafted requests. The vulnerability is associated with writing beyond the boundaries of a buffer in memory, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations
For versions prior to 4.5.9, update to version 4.5.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the network daemons and the command line interpreter to minimize the risk of exploitation. Avoid using specifically crafted requests that may trigger the buffer overflow vulnerability until the issue is resolved.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiwan