← Vulnerability feed

Vulnerability record · CVE-2024-21762 · published 9 February 2024

CVE-2024-21762: Fortinet FortiOS and FortiProxy out-of-bounds write in SSL VPN

Fortinet · Fortiproxy

FortiOS and FortiProxy contain an out-of-bounds write (CWE-787) reachable through specifically crafted requests. The flaw affects a wide range of FortiOS and FortiProxy versions and can lead to unauthorized code or command execution. It is a critical, remotely reachable issue in widely deployed perimeter security appliances.

9.8 CVSS 3.1 Critical CISA KEV since 9 Feb 2024 Known ransomware use EPSS 83% · top 0.3% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
4 Aug 2026Last modified by NVD

Description

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network reachability, CISA KEV listing with known ransomware use, and very high EPSS make this an urgent patch-first issue.

What it is

FortiOS and FortiProxy contain an out-of-bounds write (CWE-787) reachable through specifically crafted requests. The flaw affects a wide range of FortiOS and FortiProxy versions and can lead to unauthorized code or command execution. It is a critical, remotely reachable issue in widely deployed perimeter security appliances.

Impact

An unauthenticated remote attacker can execute unauthorized code or commands on the affected device. Because these are edge appliances, compromise can expose the internal network and enable further lateral movement.

Attack surface

Reachable over the network via crafted requests to the affected FortiOS/FortiProxy service, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-09 with a due date of 2024-02-16 and flags known ransomware campaign use; EPSS 30-day probability is 0.84285 (99.684th percentile), indicating active exploitation is expected.

What to do

  • Apply the Fortinet vendor patches referenced in FG-IR-24-015 for all affected FortiOS and FortiProxy versions.
  • If patching cannot be done immediately, follow CISA's required action and Fortinet's guidance, including disabling SSL VPN or applying available mitigations.
  • Restrict management and SSL VPN interfaces from untrusted networks where operationally feasible.
  • Rotate credentials and inspect for signs of compromise on any device that was exposed before patching.
  • Track CISA KEV remediation due dates and confirm all internet-facing instances are updated.

Detection

  • Monitor FortiGate/FortiProxy logs for abnormal or malformed requests to SSL VPN endpoints and for unexpected process crashes or restarts.
  • Hunt for post-exploitation indicators such as new local accounts, modified SSL VPN configurations, or unexpected outbound connections from the appliance.
  • Correlate appliance logs with network telemetry for command-and-control or lateral movement originating from the firewall/VPN device.
  • Alert on unauthorized configuration changes or new administrative sessions on FortiOS/FortiProxy devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-21762 to the Known Exploited Vulnerabilities catalog on 9 February 2024 as "Fortinet FortiOS Out-of-Bound Write Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 16 February 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21762 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed9.8CVE-2025-59718Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSOFortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An un…KEVEPSS 68%analysed9.8CVE-2024-55591FortiOS and FortiProxy authentication bypass via Node.js websocketFortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 contain an authentication bypass (CWE-288) reachable throug…KEVEPSS 94%analysed9.8CVE-2024-23113Fortinet FortiOS and related products format string remote code executionA use of externally-controlled format string (CWE-134) in Fortinet FortiOS, FortiProxy, FortiPAM and FortiSwitchManager lets an attacker execute unau…KEVEPSS 62%analysed9.8CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN heap buffer overflowFortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow (CWE-122/CWE-787) reachable through specifically crafted requests. It is a pre-au…KEVEPSS 86%analysed9.8CVE-2022-42475FortiOS and FortiProxy SSL-VPN heap buffer overflow allows remote code executionA heap-based buffer overflow (CWE-122/CWE-787) in the FortiOS and FortiProxy SSL-VPN component lets a remote attacker trigger memory corruption throu…KEVEPSS 99%analysed9.8CVE-2022-40684Fortinet FortiOS, FortiProxy and FortiSwitchManager admin interface auth bypassAn authentication bypass (CWE-288, alternate path or channel) in Fortinet FortiOS 7.2.0-7.2.1 and 7.0.0-7.0.6, FortiProxy 7.2.0 and 7.0.0-7.0.6, and …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-21762), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.