Executive brief
An out-of-bounds write vulnerability in Fortinet FortiOS and FortiProxy allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted HTTP requests. The vulnerability is known to be exploited in the wild.
Affected products
- Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17
- Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7
Timeline
- 2024-02-09: disclosed
- 2024-02-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-02-09: exploited: Reported as exploited in the wild at time of publication