PoC Index

CVE-2016-6909

HIGH 10.0EPSS 49.9%

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
49.86% chance of exploitation in the next 30 days, 99th percentile
Published
2016-08-24
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related