CVE-2024-21762: Fortinet FortiOS Out-of-Bound Write Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-02-09. EPSS: 83.4% chance of exploitation in the next 30 days.

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

Affected products

  • Fortinet FortiOS: from 6.0.0, before 6.0.18 (fixed in 6.0.18); from 6.2.0, before 6.2.16 (fixed in 6.2.16); from 6.4.0, before 6.4.15 (fixed in 6.4.15); from 7.0.0, before 7.0.14 (fixed in 7.0.14); from 7.2.0, before 7.2.7 (fixed in 7.2.7); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
  • Fortinet FortiProxy: from 1.0.0, before 2.0.14 (fixed in 2.0.14); from 7.0.0, before 7.0.15 (fixed in 7.0.15); from 7.2.0, before 7.2.9 (fixed in 7.2.9); from 7.4.0, before 7.4.3 (fixed in 7.4.3)

Published 2024-02-09. Last modified 2026-08-04.