VDB
CVE-2024-35273
CVE-2024-35273
PUBLISHED
Es bestehen mehrere Schwachstellen in Fortinet FortiAnalyzer und Fortinet FortiManager. Diese Schwachstellen betreffen die grafische Benutzeroberfläche aufgrund mehrerer Sicherheitsprobleme, darunter ein Out-of-Bounds-Write, eine unsachgemäße Neutralisierung spezieller Elemente, die in einem SQL-Befehl verwendet werden, und ein Stack-basierter Überlauf. Ein entfernter, authentisierter Angreifer kann diese Schwachstellen zur Ausführung von beliebigem Code ausnutzen.
EPSS 0.30% · 53.9th percentile
Risk Scores
EPSS Score
0.30%
53.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortinet FortiAnalyzer | |
| Fortinet | Fortinet FortiManager |
Exploit Intelligence
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-5217 (circl)
- https://security.gentoo.org/glsa/202310-04 (circl)
- https://support.apple.com/kb/HT213961 (circl)
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html (circl)
- https://crbug.com/1486441 (circl)
- http://www.openwall.com/lists/oss-security/2023/09/28/5 (circl)
- http://www.openwall.com/lists/oss-security/2023/09/28/6 (circl)
- http://www.openwall.com/lists/oss-security/2023/09/29/1 (circl)
- http://www.openwall.com/lists/oss-security/2023/09/29/2 (circl)
- http://www.openwall.com/lists/oss-security/2023/09/29/7 (circl)
…and 64 more exploits
Timeline
- Sep 28, 2023 PoC Published
- Sep 29, 2023 PoC Published
- Oct 2, 2023 PoC Published
- Oct 2, 2023 PoC Published
- Oct 3, 2023 PoC Published
- Oct 5, 2023 PoC Published
- Dec 24, 2024 PoC Published
- Jan 14, 2025 CVE Published
- Jan 14, 2025 CVE Updated
- Jan 15, 2025 EPSS Score
- Jan 31, 2025 EPSS Score
- Feb 6, 2025 Coalition ESS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0096.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0096 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-143 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-127 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-106 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-091 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-165 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-152 advisory