Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32v4-7g7v-4c6p

Опубликовано: 12 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

EPSS

Процентиль: 41%
0.00494
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 5.6
nvd
около 1 месяца назад

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

CVSS3: 5.6
fstec
около 1 месяца назад

Уязвимость демона WAD (Web Access Daemon) операционных систем FortiOS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.00494
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-121