Severity Level: Critical
Title:
FortiOS - Format String Bug in fgfmd
Timestamp:
Thursday February 8, 2024
Summary:
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Affected System:
FortiOS 7.4.0 through 7.4.2
FortiOS 7.2.0 through 7.2.6
FortiOS 7.0.0 through 7.0.13
Recommendations:
For FortiOS 7.4: Upgrade to 7.4.3 or above
For FortiOS 7.2: Upgrade to 7.2.7 or above
For FortiOS 7.0: Upgrade to 7.0.14 or above
Follow the recommended upgrade ,Click here
References:
For references , Click here