Junglewise Threat Intelligence

CVE-2024-21762: Fortinet FortiOS Out-of-Bound Write Vulnerability

CVE-2024-21762 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-02-09

Technologies: Fortinet FortiProxy SSL-VPN, Fortinet FortiOS, Fortinet FortiADC, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

An out-of-bounds write vulnerability in Fortinet FortiOS and FortiProxy allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted HTTP requests. The vulnerability is known to be exploited in the wild.

Affected products

  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7

Timeline

  • 2024-02-09: disclosed
  • 2024-02-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-02-09: exploited: Reported as exploited in the wild at time of publication

Related threats