Impact
This vulnerability is a stack‑based buffer overflow (CWE‑121) located in the WAD daemon of FortiOS. An attacker who can bypass stack protection and ASLR and who is unauthenticated can send specially crafted socket data to trigger the buffer overflow, allowing execution of arbitrary code or commands in the context of the daemon.
Affected Systems
Fortinet FortiOS versions 7.6.1 through 7.6.6 are impacted. The vendor list also references FortiPAM and FortiProxy, but the description specifically targets the FortiOS WAD daemon. Versions 7.6.7 and 8.0.0 or later contain the fix, while earlier 7.x releases remain vulnerable if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, indicating moderate severity. EPSS is not available and the issue is not listed in CISA KEV. Exploitation requires the attacker to bypass stack protection and address randomisation and to interact with the WAD daemon over sockets; it is network‑based and does not require authentication. If the proxy configuration is as described, the attack surface is greater, but in a hardened environment with stack protection and ASLR enabled the risk is reduced.
OpenCVE Enrichment