Description Preview
Overview
The vulnerability is due to an out-of-bounds write error in Fortinet's FortiOS and FortiProxy products. This error allows an attacker to execute unauthorized code or commands via specifically crafted requests. The vulnerability has been assigned the identifier CVE-2024-21762 and has a CVSS base score of 9.6, indicating a high level of severity.
Remediation
Users are advised to upgrade their FortiProxy and FortiOS to the latest versions to mitigate the vulnerability. Specifically, users should upgrade to FortiProxy version 7.4.3 or above, FortiProxy version 7.2.9 or above, FortiProxy version 7.0.15 or above, FortiProxy version 2.0.14 or above, FortiOS version 7.6.0 or above, FortiOS version 7.4.3 or above, FortiOS version 7.2.7 or above, FortiOS version 7.0.14 or above, FortiOS version 6.4.15 or above, FortiOS version 6.2.16 or above.
References
For more information about this vulnerability, please refer to the official Fortinet advisory at https://fortiguard.com/psirt/FG-IR-24-015. Additionally, the vulnerability is listed in the CISA Known Exploited Vulnerabilities Catalog at https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-21762.
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Public AdministrationPublic Administration
- Retail TradeRetail Trade
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Other Services (except Public Administration)Other Services (except Public Administration)
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Transportation & WarehousingTransportation & Warehousing
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade