Fortinet FortiWeb
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*
- >= 7.4.0, <= 7.4.1
- >= 7.2.0, <= 7.2.7
A stack-based buffer overflow vulnerability has been identified in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1. This vulnerability may allow a privileged user to execute arbitrary code by sending specially crafted CLI commands, provided the user can bypass FortiWeb's stack protections.
Exploitation of this vulnerability could lead to unauthorized execution of code or commands with elevated privileges.
Users can upgrade to Fortinet FortiWeb version 7.4.2 or above, or version 7.2.8 or above, depending on their current version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.