PT-2025-2437 · Fortinet · Fortianalyzer+1
Published
2025-01-14
·
Updated
2025-01-15
·
CVE-2024-35273
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Fortinet FortiManager versions 7.4.0 through 7.4.2
Fortinet FortiAnalyzer versions 7.4.0 through 7.4.2
Description:
The issue is related to an out-of-bounds write that allows an attacker to escalate privileges via specially crafted HTTP requests. This can potentially enable a remote attacker to execute arbitrary code or commands.
Recommendations:
For Fortinet FortiManager versions 7.4.0 through 7.4.2, consider disabling the handling of specially crafted HTTP requests until a patch is available.
For Fortinet FortiAnalyzer versions 7.4.0 through 7.4.2, restrict access to the vulnerable proxy server daemon to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortianalyzer
Fortimanager