PT-2025-2437 · Fortinet · Fortianalyzer+1

Published

2025-01-14

·

Updated

2025-01-15

·

CVE-2024-35273

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Fortinet FortiManager versions 7.4.0 through 7.4.2 Fortinet FortiAnalyzer versions 7.4.0 through 7.4.2
Description: The issue is related to an out-of-bounds write that allows an attacker to escalate privileges via specially crafted HTTP requests. This can potentially enable a remote attacker to execute arbitrary code or commands.
Recommendations: For Fortinet FortiManager versions 7.4.0 through 7.4.2, consider disabling the handling of specially crafted HTTP requests until a patch is available. For Fortinet FortiAnalyzer versions 7.4.0 through 7.4.2, restrict access to the vulnerable proxy server daemon to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-01509
CVE-2024-35273

Affected Products

Fortianalyzer
Fortimanager