CVE-2024-45324
HIGHFortiOS <6.4.15 - Memory Corruption
Title source: llmDescription
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.
Scores
CVSS v3
7.2
EPSS
0.0011
EPSS Percentile
29.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-134
Status
published
Affected Products (7)
fortinet/fortios
< 6.2.17
fortinet/fortipam
< 1.3.1
fortinet/fortiproxy
< 7.0.20
fortinet/fortiproxy
fortinet/fortiweb
< 7.0.11
fortinet/fortiweb
fortinet/fortisra
< 1.4.3
Timeline
Published
Mar 11, 2025
Tracked Since
Feb 18, 2026