CVE-2024-21762
CRITICAL KEV RANSOMWAREFortinet Fortiproxy < 2.0.14 - Out-of-Bounds Write
Title source: ruleDescription
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
Exploits (13)
nomisec
SCANNER
15 stars
by r4p3c4 · infoleak
https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check
github
SCANNER
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2024/CVE-2024-21762
nomisec
WORKING POC
1 stars
by abrewer251 · remote
https://github.com/abrewer251/CVE-2024-21762_FortiNet_PoC
Scores
CVSS v3
9.8
EPSS
0.9272
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-02-09
VulnCheck KEV
2024-02-08
InTheWild.io
2024-02-09
ENISA EUVD
EUVD-2024-19376
Ransomware Use
Confirmed
CWE
CWE-787
Status
published
Products (2)
fortinet/fortios
6.0.0 - 6.0.18
fortinet/fortiproxy
1.0.0 - 2.0.14
Published
Feb 09, 2024
KEV Added
Feb 09, 2024
Tracked Since
Feb 18, 2026