Buffer overflow via fgtupdates service
Summary
A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiManager fgtupdates service may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
| Version | Affected | Solution |
|---|---|---|
| FortiManager 7.6 | Not affected | Not Applicable |
| FortiManager 7.4 | 7.4.0 through 7.4.2 | Upgrade to 7.4.3 or above |
| FortiManager 7.2 | 7.2.0 through 7.2.10 | Upgrade to 7.2.11 or above |
| FortiManager 6.4 | 6.4 all versions | Migrate to a fixed release |
FortiManager Cloud is not affected by this vulnerability.
Workaround:
If active, disable the "fgtupdates" service.
config system interface
edit <portID>
set serviceaccess <service>
end
Where <service> is not "fgtupdates".