Impact
A buffer over‑read vulnerability exists in Fortinet FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager firmware that allows an attacker to read beyond the bounds of a data buffer, potentially exposing confidential memory contents. The flaw is categorized as CWE‑126 and can result in disclosure of sensitive information if successfully exploited. The vulnerability is reported for multiple product families, indicating broad exposure if systems remain unpatched.
Affected Systems
Both FortiOS and FortiProxy are affected. For FortiOS, versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, and 6.4 all versions may be vulnerable. For FortiProxy, versions 7.6.0 through 7.6.5, 7.4.0 through 7.4.13, 7.2 all versions, and 7.0 all versions are impacted. FortiPAM and FortiSwitchManager are also affected, but the specific impacted versions are not listed in the advisory.
Risk and Exploitability
The CVSS score of 4.1 denotes a medium severity, and the EPSS score is below 1%, suggesting a low likelihood of widespread exploitation at present. However, the vulnerability is not included in the CISA KEV catalog, meaning it is not a known actively used exploit. The exact attack vector is not specified in the provided description; it is inferred that the flaw could be triggered over a network interface or local interface if the device processes malformed input, as typical with buffer over‑read conditions.
OpenCVE Enrichment