VDB
CVE-2024-21762
CVE-2024-21762
PUBLISHED
KEV
CVSS 9.800000190734863 CRITICAL
09. Februar 2024 Fortinet hat zwei kritische Security Advisories veröffentlicht. Beide Security Advisories behandeln Sicherheitslücken, die es unauthentifizierten Angreifer:innen erlauben, Code auf betroffenen Geräten auszuführen. Fortinet gibt bezüglich einer dieser Sicherheitslücken an, dass diese potentiell bereits aktiv für Angriffe ausgenutzt wird. Update #1: 18. März 2024: Exploit-Code wurde veröffentlicht, es wird bereits über vermehrte Ausnutzung berichtet. CVE-Nummer(n): CVE-2024-21762, CVE-2024-23113 CVSS Base Score: 9.8 (CVE-2024-23113) beziehungsweise 9.6 (CVE-2024-21762)
EPSS 84.29% · 99.7th percentile
Risk Scores
CVSS 3.1
9.800000190734863
EPSS Score
84.29%
99.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiOS 7.2.0 - 7.2.6 | |
| Fortinet | FortiOS 7.0.0 - 7.0.13 | |
| Fortinet | FortiOS 6.2.0 - 6.2.15 | |
| Fortinet | FortiOS 6.0 all versions | |
| Fortinet | FortiOS 7.4.0 - 7.4.2 | |
| Fortinet | FortiOS 6.4.0 - 6.4.14 |
Timeline
- CVE Published
- Feb 8, 2024 VulnCheck KEV Exploitation
- Feb 9, 2024 CISA KEV Added
- Feb 9, 2024 VulnCheck KEV Exploitation
- Feb 10, 2024 EPSS Score
- Feb 11, 2024 VulnCheck KEV Exploitation
- Feb 12, 2024 VulnCheck KEV Exploitation
- Feb 28, 2024 VulnCheck XDB Entry
- Mar 8, 2024 EPSS Score
- Mar 13, 2024 VulnCheck XDB Entry
- Mar 18, 2024 VulnCheck KEV Exploitation
- Mar 19, 2024 VulnCheck KEV Exploitation