Home
CRITICAL: 9.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:CDefault status
unaffected
6.4.0 (semver)
affected
6.3.0 (semver)
affected
6.2.0 (semver)
affected
6.1.0 (semver)
affected
6.0.0 (semver)
affected
5.9.0 (semver)
affected
5.8.5 (semver)
affected
5.8.0 (semver)
affected
5.7.0 (semver)
affected
5.6.0 (semver)
affected
5.8.0 (semver) before 5.8.*
affected
5.7.0 (semver) before 5.7.*
affected
5.6.0 (semver) before 5.6.*
affected
Description
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.
Problem types
Execute unauthorized code or commands
Product status
6.4.0 (semver)
6.3.0 (semver)
6.2.0 (semver)
6.1.0 (semver)
6.0.0 (semver)
5.9.0 (semver)
5.8.5 (semver)
5.8.0 (semver)
5.7.0 (semver)
5.6.0 (semver)
5.8.0 (semver) before 5.8.*
5.7.0 (semver) before 5.7.*
5.6.0 (semver) before 5.6.*
References
fortiguard.com/psirt/FG-IR-21-186
fortiguard.com/psirt/FG-IR-21-186