CVE-2020-29016

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.
References
Link Resource
https://www.fortiguard.com/psirt/FG-IR-20-125 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-01-14 16:15

Updated : 2021-01-20 20:58


NVD link : CVE-2020-29016

Mitre link : CVE-2020-29016

CVE.ORG link : CVE-2020-29016


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-787

Out-of-bounds Write