Impact
A stack-based buffer overflow exists in Fortinet FortiOS, FortiPAM, and FortiProxy. The vulnerability enables a privileged authenticated attacker who can bypass stack protection and ASLR to send crafted HTTP requests that trigger the overflow, allowing execution of arbitrary code or system commands on the affected device.
Affected Systems
Affected are FortiOS 7.4.0 through 7.4.1 and all 7.2 releases; FortiPAM 1.8.0 through 1.8.2 and all earlier 1.7, 1.6, 1.5, 1.4, 1.3, 1.2, 1.1 and 1.0 editions; FortiProxy 7.4.0 through 7.4.13 and all 7.2 releases; FortiSASE 26.1.1 and 26.1.2.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate risk, and the EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a privileged or local account that can send special HTTP traffic. In summary, the attack surface is limited to environments where privileged users may be compromised or where an attacker gains temporary administrative access.
OpenCVE Enrichment