Lucene search

K
cvelistFortinetCVELIST:CVE-2021-24022
HistoryJul 20, 2021 - 10:32 a.m.

CVE-2021-24022

2021-07-2010:32:49
fortinet
www.cve.org
9
buffer overflow
fortianalyzer
fortimanager
denial of service
cli
cve-2021-24022

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the diagnose system geoip-city command with a large ip value.

CNA Affected

[
  {
    "product": "Fortinet FortiAnalyzer, FortiManager",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiAnalyzer 6.4.5 and below, 6.2.7 and below,  6.0.x; FortiManager 6.4.5 and below, 6.2.7 and below, 6.0.x"
      }
    ]
  }
]

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2021-24022