CVE-2024-35276

Summary

A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 through 7.0.12, FortiAnalyzer 6.4.0 through 6.4.14, FortiAnalyzer Cloud 7.4.1 through 7.4.3, FortiAnalyzer Cloud 7.2.1 through 7.2.5, FortiAnalyzer Cloud 7.0.1 through 7.0.11, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0.1 through 7.0.11, FortiManager Cloud 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted packets.

Affected Software

VendorProductVersion RangeStatus
FortinetFortiAnalyzer7.4.0 <= 7.4.3affected
FortinetFortiAnalyzer7.2.0 <= 7.2.5affected
FortinetFortiAnalyzer7.0.0 <= 7.0.12affected
FortinetFortiAnalyzer6.4.0 <= 6.4.14affected
FortinetFortiManager Cloud7.4.1 <= 7.4.3affected
FortinetFortiManager Cloud7.2.1 <= 7.2.5affected
FortinetFortiManager Cloud7.0.1 <= 7.0.11affected
FortinetFortiManager Cloud6.4.1 <= 6.4.7affected
FortinetFortiAnalyzer Cloud7.4.1 <= 7.4.3affected
FortinetFortiAnalyzer Cloud7.2.1 <= 7.2.5affected
FortinetFortiAnalyzer Cloud7.0.1 <= 7.0.11affected
FortinetFortiAnalyzer Cloud6.4.1 <= 6.4.7affected
FortinetFortiManager7.4.0 <= 7.4.3affected
FortinetFortiManager7.2.0 <= 7.2.5affected
FortinetFortiManager7.0.0 <= 7.0.12affected
FortinetFortiManager6.4.0 <= 6.4.14affected

Weaknesses

  • CWE-121: Execute unauthorized code or commands

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References