Heap-based buffer overflow in API v1.0 controller
Summary
A heap-based buffer overflow [CWE-122] vulnerability in FortiWeb may allow an authenticated attacker to execute arbitrary code or commands via crafted HTTP requests to the LogAccess and LogReport API controller.
Affected Products
FortiWeb version 6.4.1 and below.
FortiWeb version 6.3.16 and below.
FortiWeb version 6.2.6 and below.
Solutions
Upgrade to FortiWeb version 7.0.0 or above.
Upgrade to FortiWeb version 6.4.2 or above.
Upgrade to FortiWeb version 6.3.17 or above.
Fix for FortiWeb versions 6.2 to be confirmed.
Acknowledgement
Internally discovered and reported by Mattia Fecit of Fortinet Product Security Team.Timeline
2021-12-07: Initial publication