buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiOS version 7.0.0 through 7.0.4, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x and FortiProxy version 7.0.0 through 7.0.3, 2.0.0 through 2.0.8, 1.2.x, 1.1.x and 1.0.x allows attacker to execute unauthorized code or commands via crafted CLI `execute restore image` and `execute certificate remote` operations with the tFTP protocol.
| Link | Resource |
|---|---|
| https://fortiguard.com/advisory/FG-IR-21-206 | Not Applicable |
| https://www.fortiguard.com/psirt/FG-IR-21-206 | Vendor Advisory |
| https://fortiguard.com/advisory/FG-IR-21-206 | Not Applicable |
Configuration 1 (hide)
|
21 Nov 2024, 06:28
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.com/advisory/FG-IR-21-206 - Not Applicable |
Published : 2023-07-18 03:15
Updated : 2024-11-21 06:28
NVD link : CVE-2021-43072
Mitre link : CVE-2021-43072
CVE.ORG link : CVE-2021-43072
JSON object : View
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')