CVE-2024-21762: Out-of-bound Write in sslvpnd
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
Other sources
A out-of-bounds write vulnerability [CWE-787] in FortiOS and FortiProxy may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests.
Workaround : disable SSL VPN (disable webmode is NOT a valid workaround)
Note: This is potentially being exploited in the wild.
— FortiGuard
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
— CISA
Affected Software
Remediation
Information
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-21762?
CVE-2024-21762 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-21762?
To fix CVE-2024-21762, update FortiOS to versions 7.4.3, 7.2.7, 7.0.14, 6.4.15, 6.2.16, or 6.0.18 or FortiProxy to versions 7.4.3, 7.2.9, 7.0.15, or 2.0.14.
What systems are affected by CVE-2024-21762?
CVE-2024-21762 affects Fortinet FortiOS and FortiProxy versions as specified in the vulnerability details.
Is CVE-2024-21762 actively exploited?
Yes, there are reports indicating that CVE-2024-21762 is actively being exploited in the wild.
What is the exploit vector for CVE-2024-21762?
The exploit vector for CVE-2024-21762 involves an out-of-bounds write leading to potential remote code execution.