PT-2025-6257 · Fortinet · Fortios
Published
2025-02-11
·
Updated
2025-07-17
·
CVE-2024-35279
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
FortiOS versions 7.2.4 through 7.2.8
FortiOS versions 7.4.0 through 7.4.4
Description:
A stack-based buffer overflow vulnerability in the implementation of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol in FortiOS is related to a buffer overflow in the stack. Exploitation of this issue may allow a remote attacker to execute arbitrary code or commands by sending specially crafted UDP packets through the CAPWAP control, provided the attacker can evade FortiOS stack protections and the fabric service is running on the exposed interface.
Recommendations:
For FortiOS versions 7.2.4 through 7.2.8, update to a version that fixes the buffer overflow vulnerability in the CAPWAP control.
For FortiOS versions 7.4.0 through 7.4.4, update to a version that fixes the buffer overflow vulnerability in the CAPWAP control.
As a temporary workaround, consider restricting access to the CAPWAP control interface to minimize the risk of exploitation.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios