CVE-2024-21762

Fortinet FortiOS: Out-of-Bound Write

As of , CVE-2024-21762 in Fortinet FortiOS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 9 February 2024
US federal deadline
16 February 20247 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
KnownCISA changed it from Unknown to Known on 9 June 2025.
EPSS score
0.83Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
No score that dayThe EPSS file of the day CISA listed it has no score for it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: fortiguard.fortinet.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

CISA's description

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

The CVE record's description, from fortinet

CVE published
9 February 2024
Assigned by
fortinet
CVSS
9.6 Critical (CVSS 3.1, from the CNA)
CWE-787
Out-of-bounds Write
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Ransomware use: Unknown to Known.

FortiOS: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2018-13379SSL VPN Path TraversalFortinet FortiOSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2022-42475Heap-Based Buffer OverflowFortinet FortiOSPatch this weekRansomware use; EPSS 0.990.99
CVE-2020-12812SSL VPN Improper AuthenticationFortinet FortiOSPatch this weekRansomware use0.45
CVE-2019-5591Default ConfigurationFortinet FortiOSPatch this weekRansomware use0.18
CVE-2019-6693Use of Hard-Coded CredentialsFortinet FortiOSPatch this weekRansomware use0.06
CVE-2025-68686Exposure of Sensitive Information to an Unauthorized ActorFortinet FortiOSPatch soon0.30
CVE-2022-41328Path TraversalFortinet FortiOSPatch soon0.11
CVE-2021-44168Arbitrary File DownloadFortinet FortiOSPatch soon0.01

Read further