Advisory 53 : Vulnerability for Fortinet FortiOS Out-of-Bound Write Vulnerability.
Release Date : 09th of February 2024
Impact : HIGH / CRITICAL
TLP Rating: Clear
CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.
What is it?
Fortinet FortiOS Out-of-Bound Write vulnerability is a flaw that allows access of memory at certain locations that should not be possible.
What are the Systems affected?
The vulnerability affect the following versions of FortiOS and FortiProxy: Affected System
What this means?
A out-of-bounds write vulnerability in fortiOS may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests.
Mitigation process
Administrators are recommended to review their network for use of Fortinet FortiOS Products and upgrade to the latest releases.
See solutions to fixed Versions or use this upgrade path using our tools on the below link:
https://docs.fortinet.com/upgrade-tool
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21762
- https://www.fortiguard.com/psirt/FG-IR-24-015
- https://docs.fortinet.com/upgrade-too
- Download advisory (English): Vulnerability for Fortinet FortiOS Out-of-Bound Write Vulnerability
- Download advisory (Bislama): Vulnerabiliti blong Fortinet FortiOS Out-of-Bound Write
- Download advisory (French): Vulnérabilité Out-of-Bound Write dans FortiOS de Fortinet