CVE-2016-6909
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 49.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 49.86% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- fortinet/fortios · fortinet/fortiswitch
- Source
- cve@mitre.org
References
- http://fortiguard.com/advisory/FG-IR-16-023Vendor Advisory
- http://packetstormsecurity.com/files/138387/EGREGIOUSBLUNDER-Fortigate-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92523Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036643Third Party Advisory, VDB Entry
- https://musalbas.com/2016/08/16/equation-group-firewall-operations-catalogue.htmlThird Party Advisory
- https://www.exploit-db.com/exploits/40276/Exploit, Third Party Advisory, VDB Entry
- http://fortiguard.com/advisory/FG-IR-16-023Vendor Advisory
- http://packetstormsecurity.com/files/138387/EGREGIOUSBLUNDER-Fortigate-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92523Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036643Third Party Advisory, VDB Entry
- https://musalbas.com/2016/08/16/equation-group-firewall-operations-catalogue.htmlThird Party Advisory
- https://www.exploit-db.com/exploits/40276/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.