CVE-2016-6909

Description

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
71.56

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-6909 are affected in fortios 4.3.8NCM
Vulnerabilities CVE-2016-6909 are affected in fortiswitch 3.4.2NCM
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2016-6909)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234