CVE-2024-45324

HIGH

FortiOS <6.4.15 - Memory Corruption

Title source: llm

Description

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.

Scores

CVSS v3 7.2
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-134
Status published

Affected Products (7)

fortinet/fortios < 6.2.17
fortinet/fortipam < 1.3.1
fortinet/fortiproxy < 7.0.20
fortinet/fortiproxy
fortinet/fortiweb < 7.0.11
fortinet/fortiweb
fortinet/fortisra < 1.4.3

Timeline

Published Mar 11, 2025
Tracked Since Feb 18, 2026