{"id":"CVE-2024-21762","title":"A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…","summary":"A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"fortinet","product":"fortiproxy","affected":["fortiproxy >= 1.0.0, < 2.0.14","fortiproxy >= 7.0.0, < 7.0.15","fortiproxy >= 7.2.0, < 7.2.9","fortiproxy >= 7.4.0, < 7.4.3","fortios >= 6.0.0, < 6.0.18","fortios >= 6.2.0, < 6.2.16","fortios >= 6.4.0, < 6.4.15","fortios >= 7.0.0, < 7.0.14","fortios >= 7.2.0, < 7.2.7","fortios >= 7.4.0, < 7.4.3"],"patched":["fortiproxy 7.4.3","fortios 7.4.3"],"published":"2024-02-09","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-21762","references":[{"url":"https://fortiguard.com/psirt/FG-IR-24-015","label":"psirt@fortinet.com"},{"url":"https://fortiguard.com/psirt/FG-IR-24-015","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21762","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.83428,"epssPercentile":0.99676,"kev":true,"kevDateAdded":"2024-02-09","kevDueDate":"2024-02-16","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-04T05:36:12.484Z","exploits":{"github":13,"githubRepos":["https://github.com/BishopFox/cve-2024-21762-check","https://github.com/h4x0r-dz/CVE-2024-21762","https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check"],"checkedAt":"2026-09-21T15:26:18.326Z"},"exploitAvailable":true,"slug":"CVE-2024-21762","body":"## Overview\n\nA out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests\n\n## Affected\n\n- `fortiproxy >= 1.0.0, < 2.0.14`\n- `fortiproxy >= 7.0.0, < 7.0.15`\n- `fortiproxy >= 7.2.0, < 7.2.9`\n- `fortiproxy >= 7.4.0, < 7.4.3`\n- `fortios >= 6.0.0, < 6.0.18`\n- `fortios >= 6.2.0, < 6.2.16`\n- `fortios >= 6.4.0, < 6.4.15`\n- `fortios >= 7.0.0, < 7.0.14`\n- `fortios >= 7.2.0, < 7.2.7`\n- `fortios >= 7.4.0, < 7.4.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortiproxy 7.4.3`\n- `fortios 7.4.3`","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":16.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4695,"id":"CVE-2024-21762","ts":1788887199953,"field":"exploit_available","old":"false","new":"true"},{"seq":3578,"id":"CVE-2024-21762","ts":1788886316433,"field":"exploit_available","old":"true","new":"false"},{"seq":2432,"id":"CVE-2024-21762","ts":1788882985172,"field":"exploit_available","old":"false","new":"true"},{"seq":1461,"id":"CVE-2024-21762","ts":1788882398464,"field":"exploit_available","old":"true","new":"false"},{"seq":575,"id":"CVE-2024-21762","ts":1788881835109,"field":"exploit_available","old":"false","new":"true"}]}