Описание
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
EPSS
5.6 Medium
CVSS3
8.1 High
CVSS3
Дефекты
Связанные уязвимости
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Уязвимость демона WAD (Web Access Daemon) операционных систем FortiOS, позволяющая нарушителю выполнить произвольный код
EPSS
5.6 Medium
CVSS3
8.1 High
CVSS3