CVE-2016-6909
EUVD-2016-779424.08.2016, 16:30
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortios | 4.1.0 ≤ 𝑥 < 4.1.11 |
| fortinet | fortios | 4.2.0 ≤ 𝑥 < 4.2.13 |
| fortinet | fortios | 4.3.0 ≤ 𝑥 < 4.3.9 |
| fortinet | fortiswitch | 𝑥 ≤ 3.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References