1000
VMScore

CVE-2016-6909

Published: 24/08/2016 Updated: 22/05/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x prior to 4.1.11, 4.2.x prior to 4.2.13, and 4.3.x prior to 4.3.9 and FortiSwitch prior to 3.4.3 allows remote malicious users to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios

fortinet fortiswitch

Exploits

# Exploit Title: Fortigate Firewalls - Remote Code Execution (EGREGIOUSBLUNDER) # Date: 19-08-2016 # Exploit Author: Shadow Brokers # Vendor Homepage: wwwfortinetcom/products/fortigate/ Full Exploit: githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/40276zip ...