Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4chx-4wv3-ph6v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.

EPSS

Процентиль: 84%
0.02177
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.

CVSS3: 9.8
fstec
около 5 лет назад

Уязвимость межсетевого экрана веб-приложений FortiWeb, связанная с записью данных за пределами буфера в памяти, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 84%
0.02177
Низкий

Дефекты

CWE-787