← Back

CVE-2024-35279

nvd nist
Published: Feb 11, 2025Modified: Jul 17, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)

Description

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack protections and provided the fabric service is running on the exposed interface.

Affected (2)

Products: Fortinet: Fortios
1 product
Fortios
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.2.4 to 7.2.9
From 7.4.0 to 7.4.5

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.