CVE-2024-21762
Fortinet FortiOS and FortiProxy versions up to 7.4.2 are vulnerable to an out‑of‑bounds write that lets attackers run arbitrary code without authentication. The flaw can be triggered by specially crafted requests and has been actively exploited. A critical CVSS score of 9.8 reflects the high impact and ease of exploitation.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Fortinet FortiOS 6.0.0–7.4.2 and FortiProxy 1.0.0–7.4.2 (various sub‑versions) – typical users are network administrators running these firewalls or proxy appliances.
Real-world impact
An attacker can execute arbitrary code or commands on the device, potentially taking full control of the firewall or proxy, compromising network traffic, and enabling further attacks.
Why this severity
The CVSS score of 9.8 comes from the fact that the vulnerability is remote, requires no user interaction, and gives attackers full confidentiality, integrity, and availability impact. The low attack complexity and lack of required privileges make it very easy to exploit.
What to do about it
- 01Check Fortinet’s advisory for CVE-2024-21762 and apply the recommended mitigation.
- 02If no mitigation is available, discontinue use of the affected product.
CISA KEV required action
Timeline
- Feb 9, 2024 · Feb 9, 2024Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Feb 9, 2024 · Feb 9, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Feb 16, 2024 · Feb 16, 2024CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- fortiguard.com/psirt/FG-IR-24-015vendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource