Fortinet Multiple Products Format String Vulnerability
Fortinet FortiOS 버전 7.4.0부터 7.4.2까지, 7.2.0부터 7.2.6까지, 7.0.0부터 7.0.13까지, FortiProxy 버전 7.4.0부터 7.4.2까지, 7.2.0부터 7.2.8까지, 7.0.0부터 7.0.14까지, FortiPAM 버전 1.2.0, 1.1.0부터 1.1.2까지, 1.0.0부터 1.0.3까지, FortiSwitchManager 버전 7.2.0부터 7.2.3까지, 7.0.0부터 7.0.3까지에는 외부에서 제어되는 포맷 문자열 사용 취약점이 있으며, 공격자는 특수하게 조작된 패킷을 통해 승인되지 않은 코드 또는 명령을 실행할 수 있습니다.
Fortinet FortiOS 버전 7.4.0부터 7.4.2까지, 7.2.0부터 7.2.6까지, 7.0.0부터 7.0.13까지, FortiProxy 버전 7.4.0부터 7.4.2까지, 7.2.0부터 7.2.8까지, 7.0.0부터 7.0.14까지, FortiPAM 버전 1.2.0, 1.1.0부터 1.1.2까지, 1.0.0부터 1.0.3까지, FortiSwitchManager 버전 7.2.0부터 7.2.3까지, 7.0.0부터 7.0.3까지에는 외부에서 제어되는 포맷 문자열 사용 취약점이 있으며, 공격자는 특수하게 조작된 패킷을 통해 승인되지 않은 코드 또는 명령을 실행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.