PT-2023-8534 · Fortinet · Fortiproxy+1

Published

2023-02-09

·

Updated

2026-05-25

·

CVE-2024-21762

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions 6.0.0 through 7.4.2 and FortiProxy versions 2.0.0 through 7.4.2
Description Fortinet FortiOS and FortiProxy contain an out-of-bounds write vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted HTTP requests. This vulnerability is actively being exploited in the wild, with approximately 150,000 systems potentially affected globally, with a high concentration in the United States. Exploitation allows for remote code execution (RCE). A proof-of-concept (PoC) exploit is available. The vulnerability resides in the sslvpnd component.
Recommendations Fortinet FortiOS versions 6.0.0 through 7.4.2: Upgrade to a fixed version or disable SSL VPN as a temporary workaround. FortiProxy versions 2.0.0 through 7.4.2: Upgrade to a fixed version or disable SSL VPN as a temporary workaround.

Exploit

Fix

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-01125
CVE-2024-21762
FORTINETSSLVPN_CVE_2024_21762

Affected Products

Fortios
Fortiproxy