Fortinet FortiWeb
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*
- >= 8.0.0, <= 8.0.3
- >= 7.6.0, <= 7.6.6
- >= 7.4.0, <= 7.4.11
- ~7.2
- ~7.0
A stack-based buffer overflow vulnerability has been identified in Fortinet FortiWeb versions 8.0.0 through 8.0.3, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, as well as all versions of FortiWeb 7.2 and 7.0. This vulnerability may allow a remote authenticated attacker who can bypass stack protection and Address Space Layout Randomization (ASLR) to execute arbitrary code or commands by sending crafted HTTP requests.
Exploitation of this vulnerability could lead to unauthorized execution of code or commands on the affected system.
Users of Fortinet FortiWeb should upgrade to FortiWeb 8.0.4 or above, FortiWeb 7.6.7 or above, FortiWeb 7.4.12 or above. Users on FortiWeb 7.2 or 7.0 should migrate to a fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.