Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://fortiguard.com/advisory/FG-IR-21-132 | vendor advisory |