← All CVEs

CVE-2016-6909

critical · 9.8

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

9.8
CVSS
49.9%
EPSS (exploit prob.)
99th
EPSS percentile
2016-08-24
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
fortinetfortios>= 4.1.0, < 4.1.11
fortinetfortios>= 4.2.0, < 4.2.13
fortinetfortios>= 4.3.0, < 4.3.9
fortinetfortiswitch<= 3.4.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-6909