Stack Buffer Overflow in Log Report

MonitorCVSS 5.9FG-IR-26-148Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityHigh
User InteractionNone needed
Summary

A stack buffer overflow vulnerability exists in log report handling for Fortinet products. An authenticated user with administrator privileges can trigger the overflow when generating or accessing log reports, potentially allowing arbitrary code execution on the affected device.

What this means
What could happen
An attacker with admin credentials could execute arbitrary code on FortiOS, FortiPAM, or FortiProxy devices, potentially gaining full control of the security appliance and access to protected network resources or credentials stored within it.
Who's at risk
Organizations using Fortinet security appliances (FortiOS on FortiGate firewalls, FortiPAM for privileged account management, or FortiProxy for web proxy/filtering) are affected. This is most critical for utilities and critical infrastructure where these devices protect SCADA networks, operator workstations, or administrative access to control systems.
How it could be exploited
An authenticated administrator accesses the log report feature through the management interface. By supplying specially crafted input or triggering report generation with malicious parameters, the attacker overflows a stack buffer, potentially executing arbitrary code with the privileges of the FortiOS/FortiPAM/FortiProxy process.
Prerequisites
  • Valid administrator credentials
  • Access to management interface (web UI, API, or CLI)
  • Knowledge of log report function parameters or ability to manipulate report generation
Requires high-level authenticationHigh complexity attackLow exploit probability (EPSS 0.6%)Affects security appliances controlling network access to OT systems
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (7)
7 with fix
ProductAffected VersionsFix Status
FortiOS7.4.0 - 7.4.17.4.2+
FortiOS7.2 all versionsMigrate to fixed release
FortiPAM1.8.0 - 1.8.21.8.3+
FortiPAM1.7 all versionsMigrate to fixed release
FortiPAM1.6 all versions and 6 moreMigrate to fixed release
FortiProxy7.4.0 - 7.4.137.4.14+
FortiProxy7.2 all versionsMigrate to fixed release
Remediation & Mitigation
0/8
Do now
0/1
HARDENINGRestrict admin access to management interfaces to trusted networks via firewall rules or network segmentation
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

FortiOS
HOTFIXUpdate FortiOS 7.4.x to version 7.4.2 or later
HOTFIXMigrate FortiOS 7.2 to a supported fixed release (7.4.2+ or later stable version)
FortiPAM
HOTFIXUpdate FortiPAM 1.8.x to version 1.8.3 or later
HOTFIXMigrate FortiPAM 1.7 and earlier versions to a supported fixed release
FortiProxy
HOTFIXUpdate FortiProxy 7.4.x to version 7.4.14 or later
HOTFIXMigrate FortiProxy 7.2 to a supported fixed release (7.4.14+ or later stable version)
Long-term hardening
0/1
HARDENINGDisable unnecessary administrative access protocols (e.g., HTTP for management) and enforce HTTPS with strong authentication
API: /api/v1/advisories/87996b55-35db-481b-8fba-19505984c009

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Stack Buffer Overflow in Log Report | CVSS 5.9 - OTPulse