A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
🚨 Marked as known exploited on April 24th, 2025 (about 1 month ago).
CVE ID: CVE-2024-21762
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor: Fortinet
Product: FortiProxy, FortiOS
EPSS Score: 92.52% (probability of being exploited)
EPSS Percentile: 99.72% (scored less or equal to compared to others)
EPSS Date: 2025-05-23 (when was this score calculated)
SSVC Exploitation: active
SSVC Technical Impact: total
SSVC Automatable: true