A heap-based buffer overflow in Fortinet FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15, 6.2.0 through 6.2.17, FortiManager Cloud 7.6.2, 7.4.1 through 7.4.5, 7.2.1 through 7.2.8, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7, FortiAnalyzer Cloud 7.4.1 through 7.4.5, 7.2.1 through 7.2.8, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7, FortiProxy 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.12, 7.0.0 through 7.0.19, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiAnalyzer 7.6.0 through 7.6.2, 7.4.0 through 7.4.5, 7.2.0 through 7.2.8, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, 6.2.0 through 6.2.13, 6.0.0 through 6.0.12, FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, 6.2.0 through 6.2.13, 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via specifically crafted requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortianalyzer | 7.0.0 | 7.0.14 |
| fortinet / fortianalyzer | 7.2.0 | 7.2.10 |
| fortinet / fortianalyzer | 7.4.0 | 7.4.6 |
| fortinet / fortianalyzer | 7.6.0 | 7.6.3 |
| fortinet / fortianalyzer_cloud | 6.4.1 | 7.0.14 |
| fortinet / fortianalyzer_cloud | 7.2.1 | 7.2.10 |
| fortinet / fortianalyzer_cloud | 7.4.1 | 7.4.6 |
| fortinet / fortimanager | 6.0.0 | 7.0.14 |
| fortinet / fortimanager | 7.2.0 | 7.2.10 |
| fortinet / fortimanager | 7.4.0 | 7.4.6 |
| fortinet / fortimanager | 7.6.0 | 7.6.2 |
| fortinet / fortimanager_cloud | 6.4.1 | 7.0.14 |
| fortinet / fortimanager_cloud | 7.2.1 | 7.2.10 |
| fortinet / fortimanager_cloud | 7.4.1 | 7.4.6 |
| fortinet / fortimanager_cloud | 7.6.2 | 7.6.2.x |
| fortinet / fortios | 6.2.0 | 6.4.16 |
| fortinet / fortios | 7.0.0 | 7.0.17 |
| fortinet / fortios | 7.2.0 | 7.2.11 |
| fortinet / fortios | 7.4.0 | 7.4.7 |
| fortinet / fortios | 7.6.0 | 7.6.3 |
| fortinet / fortiproxy | 1.0.0 | 7.0.20 |
| fortinet / fortiproxy | 7.2.0 | 7.2.13 |
| fortinet / fortiproxy | 7.4.0 | 7.4.8 |
| fortinet / fortiproxy | 7.6.0 | 7.6.0.x |