Buffer Overflow in LLDP OUI field
Summary
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability [CWE-120] in FortiSwitchAXFixed may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.
| Version | Affected | Solution |
|---|---|---|
| FortiSwitchAXFixed 1.0 | 1.0.0 through 1.0.1 | Upgrade to 1.0.2 or above |
Acknowledgement
Internally discovered and reported by Yonghui Han of Fortinet Product Security team.Timeline
2026-03-10: Initial publication