← Back

CVE-2024-35276

nvd nist
Published: Jan 14, 2025Modified: Jul 8, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 through 7.0.12, FortiAnalyzer 6.4.0 through 6.4.14, FortiAnalyzer Cloud 7.4.1 through 7.4.3, FortiAnalyzer Cloud 7.2.1 through 7.2.5, FortiAnalyzer Cloud 7.0.1 through 7.0.11, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0.1 through 7.0.11, FortiManager Cloud 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted packets.

Affected (14)

4 products
Fortianalyzer
Fortianalyzer Cloud
Fortimanager
Fortimanager Cloud
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 6.4.15
From 7.0.0 to 7.0.13
From 7.2.0 to 7.2.6
From 7.4.0 to 7.4.4
Fortinet
From 6.4.1 to 7.0.12
From 7.2.1 to 7.2.6
From 7.4.1 to 7.4.4
Fortinet
From 6.4.0 to 6.4.15
From 7.0.0 to 7.0.13
From 7.2.0 to 7.2.6
From 7.4.0 to 7.4.4
Fortinet
From 6.4.1 to 7.0.12
From 7.2.1 to 7.2.6
From 7.4.1 to 7.4.4

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.