CVE-2016-6909
24.08.2016, 16:30
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortios | 4.1.0 ≤ 𝑥 < 4.1.11 |
fortinet | fortios | 4.2.0 ≤ 𝑥 < 4.2.13 |
fortinet | fortios | 4.3.0 ≤ 𝑥 < 4.3.9 |
fortinet | fortiswitch | 𝑥 ≤ 3.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References