Out-of-bounds write in Fortinet, Inc products - CVE-2024-35273
Published: April 10, 2025
Vulnerability identifier: #VU107359
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35273
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in sndproxy. An authenticated attacker can execute arbitrary code or commands via specially crafted HTTP requests.
Affected software
FortiAnalyzer
FortiManager
FortiAnalyzer Cloud
FortiManager
FortiAnalyzer Cloud
How to mitigate CVE-2024-35273
Install update from vendor's website.
FortiAnalyzer - update to 7.4.4
FortiManager - update to 7.4.3
FortiAnalyzer Cloud - update to 7.4.3
FortiManager - update to 7.4.3
FortiAnalyzer Cloud - update to 7.4.3