CVE-2024-45324

HIGH

FortiOS <6.4.15 - Memory Corruption

Title source: llm
STIX 2.1

Description

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.

Scores

CVSS v3 7.2
EPSS 0.0022
EPSS Percentile 44.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-134
Status published
Products (7)
fortinet/fortios 6.2.0 - 6.2.17
fortinet/fortipam 1.0.0 - 1.3.1
fortinet/fortiproxy 7.6.0
fortinet/fortiproxy 7.0.0 - 7.0.20
fortinet/fortisra 1.4.0 - 1.4.3
fortinet/fortiweb 7.6.0
fortinet/fortiweb 7.0.0 - 7.0.11
Published Mar 11, 2025
Tracked Since Feb 18, 2026