CVE-2024-21762

CRITICAL KEV RANSOMWARE

Fortinet Fortiproxy < 2.0.14 - Out-of-Bounds Write

Title source: rule

Description

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

Exploits (13)

nomisec WORKING POC 145 stars
by h4x0r-dz · dos
https://github.com/h4x0r-dz/CVE-2024-21762
nomisec SCANNER 106 stars
by BishopFox · infoleak
https://github.com/BishopFox/cve-2024-21762-check
nomisec SCANNER 15 stars
by r4p3c4 · infoleak
https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check
nomisec WORKING POC 13 stars
by d0rb · remote
https://github.com/d0rb/CVE-2024-21762
github SCANNER 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2024/CVE-2024-21762
nomisec WORKING POC 1 stars
by abrewer251 · remote
https://github.com/abrewer251/CVE-2024-21762_FortiNet_PoC
nomisec SCANNER 1 stars
by rdoix · infoleak
https://github.com/rdoix/cve-2024-21762-checker
nomisec WORKING POC
by 0x0asif · poc
https://github.com/0x0asif/CVE-2024-21762
nomisec WORKING POC
by 0x13-ByteZer0 · remote
https://github.com/0x13-ByteZer0/CVE-2024-21762
nomisec WORKING POC
by CrackerCat · poc
https://github.com/CrackerCat/cve-2024-21762-poc
nomisec SCANNER
by deFr0ggy · poc
https://github.com/deFr0ggy/CVE-2024-21762-Checker

Scores

CVSS v3 9.8
EPSS 0.9272
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-02-09
VulnCheck KEV 2024-02-08
InTheWild.io 2024-02-09
ENISA EUVD EUVD-2024-19376
Ransomware Use Confirmed
CWE
CWE-787
Status published
Products (2)
fortinet/fortios 6.0.0 - 6.0.18
fortinet/fortiproxy 1.0.0 - 2.0.14
Published Feb 09, 2024
KEV Added Feb 09, 2024
Tracked Since Feb 18, 2026