Format string error in FortiOS - CVE-2024-45324
Published: March 12, 2025
Vulnerability identifier: #VU105622
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45324
CWE-ID: CWE-134
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a format string error. A remote user can send a specially crafted HTTP request that contains format string specifiers and execute arbitrary code with elevated privileges.
Affected software
FortiOS
FortiPAM
FortiSRA
FortiWeb
FortiProxy
FortiPAM
FortiSRA
FortiWeb
FortiProxy
How to mitigate CVE-2024-45324
Install updates from vendor's website.
FortiOS - addressed in versions 6.4.16, 7.0.16, 7.2.10, 7.4.5
FortiPAM - addressed in versions 1.3.2, 1.4.3
FortiSRA - update to 1.4.3
FortiWeb - addressed in versions 7.0.11, 7.2.11, 7.4.6, 7.6.1
FortiProxy - addressed in versions 7.0.20, 7.2.13, 7.4.7, 7.6.1
FortiPAM - addressed in versions 1.3.2, 1.4.3
FortiSRA - update to 1.4.3
FortiWeb - addressed in versions 7.0.11, 7.2.11, 7.4.6, 7.6.1
FortiProxy - addressed in versions 7.0.20, 7.2.13, 7.4.7, 7.6.1