---
id: CVE-2024-21762
title: >-
  A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0
  through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through
  6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0
  through 7…
summary: >-
  A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0
  through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through
  6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0
  through 7…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: fortinet
product: fortiproxy
affected:
  - 'fortiproxy >= 1.0.0, < 2.0.14'
  - 'fortiproxy >= 7.0.0, < 7.0.15'
  - 'fortiproxy >= 7.2.0, < 7.2.9'
  - 'fortiproxy >= 7.4.0, < 7.4.3'
  - 'fortios >= 6.0.0, < 6.0.18'
  - 'fortios >= 6.2.0, < 6.2.16'
  - 'fortios >= 6.4.0, < 6.4.15'
  - 'fortios >= 7.0.0, < 7.0.14'
  - 'fortios >= 7.2.0, < 7.2.7'
  - 'fortios >= 7.4.0, < 7.4.3'
patched:
  - fortiproxy 7.4.3
  - fortios 7.4.3
published: '2024-02-09'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-21762'
references:
  - url: 'https://fortiguard.com/psirt/FG-IR-24-015'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.com/psirt/FG-IR-24-015'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21762
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.83428
epssPercentile: 0.99675
kev: true
kevDateAdded: '2024-02-09'
kevDueDate: '2024-02-16'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-04T05:36:12.484Z'
exploits:
  github: 13
  githubRepos:
    - 'https://github.com/BishopFox/cve-2024-21762-check'
    - 'https://github.com/h4x0r-dz/CVE-2024-21762'
    - >-
      https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check
  checkedAt: '2026-09-25T08:20:42.772Z'
exploitAvailable: true
---

## Overview

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

## Affected

- `fortiproxy >= 1.0.0, < 2.0.14`
- `fortiproxy >= 7.0.0, < 7.0.15`
- `fortiproxy >= 7.2.0, < 7.2.9`
- `fortiproxy >= 7.4.0, < 7.4.3`
- `fortios >= 6.0.0, < 6.0.18`
- `fortios >= 6.2.0, < 6.2.16`
- `fortios >= 6.4.0, < 6.4.15`
- `fortios >= 7.0.0, < 7.0.14`
- `fortios >= 7.2.0, < 7.2.7`
- `fortios >= 7.4.0, < 7.4.3`

## Remediation

Upgrade past the affected range:

- `fortiproxy 7.4.3`
- `fortios 7.4.3`
