Lucene search

K
cveFortinetCVE-2021-24022
HistoryJul 20, 2021 - 11:15 a.m.

CVE-2021-24022

2021-07-2011:15:11
CWE-120
fortinet
web.nvd.nist.gov
26
4
cve-2021-24022
buffer overflow
vulnerability
fortianalyzer
fortimanager
cli
dos
nvd
cve

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

4.9

Confidence

High

EPSS

0

Percentile

5.1%

A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the diagnose system geoip-city command with a large ip value.

Affected configurations

Nvd
Node
fortinetfortianalyzerRange6.0.06.2.8
OR
fortinetfortianalyzerRange6.4.06.4.6
OR
fortinetfortimanagerRange6.0.06.2.8
OR
fortinetfortimanagerRange6.4.06.4.6
VendorProductVersionCPE
fortinetfortianalyzer*cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
fortinetfortimanager*cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Fortinet FortiAnalyzer, FortiManager",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiAnalyzer 6.4.5 and below, 6.2.7 and below,  6.0.x; FortiManager 6.4.5 and below, 6.2.7 and below, 6.0.x"
      }
    ]
  }
]

Social References

More

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

4.9

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2021-24022