VYPR
Medium severity6.7NVD Advisory· Published Jul 20, 2021· Updated Jun 17, 2026

CVE-2021-24022

CVE-2021-24022

Description

A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the diagnose system geoip-city command with a large ip value.

Affected products

5
  • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.0.0,<6.2.8
    • (no CPE)range: <=6.4.5, <=6.2.7, 6.0.x
    • (no CPE)range: FortiAnalyzer 6.4.5 and below, 6.2.7 and below, 6.0.x; FortiManager 6.4.5 and below, 6.2.7 and below, 6.0.x
  • cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >=6.0.0,<6.2.8
    • (no CPE)range: <=6.4.5, <=6.2.7, 6.0.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.