Stack-based Buffer Overflow in FortiOS and FortiProxy Products
CVE-2021-44170
6.7MEDIUM
Summary
A stack-based buffer overflow vulnerability exists in the command line interpreter of FortiOS and FortiProxy. An attacker with authenticated access can exploit this flaw by supplying specially crafted command line arguments, which could enable them to execute unauthorized code or commands, potentially compromising system integrity and confidentiality.
Affected Version(s)
Fortinet FortiProxy, FortiOS FortiOS before 7.0.4; FortiProxy before 2.0.8
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved