CVE-2024-21758
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 121
CWE ID 120
Summary
CVE-2024-21758 is a critical vulnerability affecting Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1. This issue involves a stack-based buffer overflow, enabling a privileged user to inject malicious code through specially crafted CLI commands. Successful exploitation may lead to arbitrary code execution, potentially compromising the FortiWeb system. It is essential for organizations using these FortiWeb versions to apply the necessary patches to prevent potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.