CVE-2024-21758

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 121
CWE ID 120

Summary

CVE-2024-21758 is a critical vulnerability affecting Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1. This issue involves a stack-based buffer overflow, enabling a privileged user to inject malicious code through specially crafted CLI commands. Successful exploitation may lead to arbitrary code execution, potentially compromising the FortiWeb system. It is essential for organizations using these FortiWeb versions to apply the necessary patches to prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share