CVE-2026-59837

Siemens ProductCERT Advisory SSA-864900

Beschreibung

Ein Stapel-basierter Pufferüberlauf-Schwachpunkt in Fortinet FortiOS 7.4.0 bis 7.4.1, FortiOS 7.2 allen Versionen, FortiPAM 1.8.0 bis 1.8.2, FortiPAM 1.7 allen Versionen, FortiPAM 1.6 allen Versionen, FortiPAM 1.5 allen Versionen, FortiPAM 1.4 allen Versionen, FortiPAM 1.3 allen Versionen, FortiPAM 1.2 allen Versionen, FortiPAM 1.1 allen Versionen, FortiPAM 1.0 allen Versionen, FortiProxy 7.4.0 bis 7.4.13 und FortiProxy 7.2 allen Versionen kann es einem privilegierten authentifizierten Angreifer ermöglichen, Stapelschutz und ASLR zu umgehen und über gefälschte HTTP-Anfragen beliebigen Code oder Befehle auszuführen.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.6
Quelle: nvd-v3
49.9 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2025-01-14 14:08 UTC
CWE-121

Weakness-Klassen (CWE)

  • CWE-121Variant

    Stack-based Buffer Overflow

    A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-11 13:19 UTC· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
    • Affected: RUGGEDCOM APE1808
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-864900.html

Betroffene Betriebssysteme

  • mobile

    fortinet / fortios6.0.0

  • mobile

    fortinet / fortios6.0.1

  • mobile

    fortinet / fortios6.0.10

  • mobile

    fortinet / fortios6.0.11

  • mobile

    fortinet / fortios6.0.12

  • mobile

    fortinet / fortios6.0.13

  • mobile

    fortinet / fortios6.0.14

  • mobile

    fortinet / fortios6.0.15

  • mobile

    fortinet / fortios6.0.16

  • mobile

    fortinet / fortios6.0.17

  • mobile

    fortinet / fortios6.0.18

  • mobile

    fortinet / fortios6.0.2

  • mobile

    fortinet / fortios6.0.3

  • mobile

    fortinet / fortios6.0.4

  • mobile

    fortinet / fortios6.0.5

  • mobile

    fortinet / fortios6.0.6

  • mobile

    fortinet / fortios6.0.7

  • mobile

    fortinet / fortios6.0.8

  • mobile

    fortinet / fortios6.0.9

  • mobile

    fortinet / fortios6.2.0

  • mobile

    fortinet / fortios6.2.1

  • mobile

    fortinet / fortios6.2.10

  • mobile

    fortinet / fortios6.2.11

  • mobile

    fortinet / fortios6.2.12

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • fortinet

    fortiproxy2.0.0 – 7.4.4

  • fortinet

    fortiproxy7.0.0 – 7.0.22

  • fortinet

    fortiproxy7.0.0 – 7.0.23

  • fortinet

    fortiproxy7.0.0 – 7.4.4

  • fortinet

    fortiproxy7.0.0 – 7.4.9

  • fortinet

    fortiproxy7.0.0 – 7.6.4

  • fortinet

    fortiproxy7.0.5 – 7.4.9

  • fortinet

    fortiproxy7.2.0 – 7.2.15

  • fortinet

    fortiproxy7.2.0 – 7.4.14

  • fortinet

    fortiproxy7.2.0 – 7.6.5

  • fortinet

    fortiproxy7.4.0 – 7.4.11

  • fortinet

    fortiproxy7.4.0 – 7.4.13

  • fortinet

    fortiproxy7.6.0 – 7.6.2

  • fortinet

    fortiproxy7.6.0 – 7.6.3

  • fortinet

    fortiproxy7.6.0 – 7.6.4

  • fortinet

    fortiproxy7.6.0 – 7.6.5

  • fortinet

    fortiproxy7.6.0 – 7.6.6

  • fortinet

    fortisase

  • fortinet

    fortiswitchmanager7.0.0 – 7.0.6

  • fortinet

    fortiswitchmanager7.2.0 – 7.2.7

  • fortinet

    fortiweb7.4.0 – 7.4.9

  • fortinet

    fortiweb7.6.0 – 7.6.4

  • fortinet

    fortiweb

Quellen & Referenzen

Verknüpfte CVEs

3 weitere CVEs anzeigen
IDCVE-2026-59837