VULNERABILITY INTELLIGENCE
CVE-2016-6909
CVSS score9.8 CRITICAL
EPSS probability49.86%
CISA KEVNot currently listed
Published2016-08-24
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Primary references
- cve@mitre.org — Vendor Advisory
- cve@mitre.org — Exploit, Third Party Advisory, VDB Entry
- cve@mitre.org — Third Party Advisory, VDB Entry
- cve@mitre.org — Third Party Advisory, VDB Entry
- cve@mitre.org — Third Party Advisory
- cve@mitre.org — Exploit, Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Third Party Advisory, VDB Entry