Stack-Based Buffer Overflow in Fortinet FortiAnalyzer and FortiManager Products
CVE-2024-35276

5MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
14 January 2025

What is CVE-2024-35276?

A stack-based buffer overflow vulnerability in multiple versions of Fortinet's FortiAnalyzer and FortiManager products could allow an attacker to execute unauthorized code or commands through specially crafted packets. This presents a significant risk, necessitating immediate attention for those using affected versions to mitigate potential exploitation.

Affected Version(s)

FortiAnalyzer 7.4.0 <= 7.4.3

FortiAnalyzer 7.2.0 <= 7.2.5

FortiAnalyzer 7.0.0 <= 7.0.12

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.