A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Fortios | Fortinet | 6.2.0 (including) | 7.0.14 (excluding) |
| Fortios | Fortinet | 7.2.0 (including) | 7.2.7 (excluding) |
| Fortios | Fortinet | 7.4.0 (including) | 7.4.0 (including) |