Description
A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI `execute backup-local rename` and `execute backup-local show` operations.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiWeb version 7.0.2 or above Please upgrade to FortiWeb version 6.3.20 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-36910 | A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI `execute backup-local rename` and `execute backup-local show` operations. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-164 |
|
History
Wed, 23 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-23T14:47:25.480Z
Reserved: 2022-06-16T11:14:43.763Z
Link: CVE-2022-33871
Updated: 2024-08-03T08:09:22.682Z
Status : Modified
Published: 2023-02-16T19:15:12.730
Modified: 2024-11-21T07:08:29.840
Link: CVE-2022-33871
No data.
OpenCVE Enrichment
No data.
EUVD