VULNERABILITY INTELLIGENCE

CVE-2016-6909

CVSS score9.8 CRITICAL
EPSS probability49.86%
CISA KEVNot currently listed
Published2016-08-24
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

Weakness classification

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Primary references