CVE-2024-21762
Fortinet FortiOS Out-of-Bound Write Vulnerability
CVSS
9.8
Critical
EPSS
84.3%
p100
KEV
YES
Feb 9, 2024
Exploit Today
80
0-100
Published: Feb 9, 2024 · Last modified: Aug 4, 2026 · CWE-787
Product
Fortinet / FortiOS
Vulnerability
Fortinet FortiOS Out-of-Bound Write Vulnerability
Added to KEV
Feb 9, 2024
Remediate by
Feb 16, 2024
Known ransomware use
Yes
Summary description
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://fortiguard.fortinet.com/psirt/FG-IR-24-015 ; https://nvd.nist.gov/vuln/detail/CVE-2024-21762
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests