CVE-2024-45324
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy ver
Description
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.
Weakness: CWE-134
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiPAM | Identity / IAM / MFA | cna-assigner |
| Fortinet | FortiProxy | SASE / SSE / Secure Web | cna-assigner |
| Fortinet | FortiSRA | VPN & Remote Access | cna-assigner |
| Fortinet | FortiWeb | Web & Application Security | cna-assigner |
Vendor-reported affected versions (5)
- Fortinet · FortiPAM
- Fortinet · FortiWeb
- Fortinet · FortiProxy
- Fortinet · FortiSRA
- Fortinet · FortiOS
Vendor remediation
Upgrade to FortiPAM version 1.5.0 or above Upgrade to FortiPAM version 1.4.3 or above Upgrade to upcoming FortiPAM version 1.3.2 or above Upgrade to FortiProxy version 7.6.1 or above Upgrade to FortiProxy version 7.4.7 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.5 or above Upgrade to FortiOS version 7.2.10 or above Upgrade to FortiOS version 7.0.16 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiOS version 6.2.17 or above Upgrade to upcoming FortiAuthenticator version 7.0.0 or above Upgrade to FortiWeb version 7.6.1 or above Upgrade to FortiWeb version 7.4.6 or above Upgrade to FortiWeb version 7.2.11 or above Upgrade to FortiWeb version 7.0.11 or above Fortinet remediated this issue in FortiSASE version 24.4.b1 and hence customers do not need to perform any action. Upgrade to FortiSRA version 1.5.0 or above Upgrade to FortiSRA version 1.4.3 or above