Fortinet FortiOS
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*
- >= 7.6.0, <= 7.6.3
- >= 7.4.0, <= 7.4.8
- >= 7.2.0, <= 7.2.11
A vulnerability allowing out-of-bounds write has been identified in Fortinet FortiOS versions 7.6.0 to 7.6.3, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.11. This vulnerability exists within the CAPWAP daemon and can be exploited by an attacker controlling an authenticated FortiAP, FortiExtender, or FortiSwitch, to execute unauthorized code or commands on the FortiGate device.
Exploitation of this vulnerability allows for unauthorized code execution on the affected FortiGate device.
Users can upgrade Fortinet FortiOS to version 7.6.4 or above, 7.4.9 or above, or 7.2.12 or above, depending on their current version. Consult the Fortinet upgrade tool for guidance. As an alternative, the CAPWAP daemon can be disabled by modifying the system global settings.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.