A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a?&web_view=true
https://securityaffairs.com/158765/apt/china-linked-apt-dutch-mod.html
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
https://www.theregister.com/2024/02/06/dutch_defense_china_cyberattack/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a
https://www.tenable.com/blog/volt-typhoon-cybersecurity-advisory
https://thehackernews.com/2023/03/from-ransomware-to-cyber-espionage-55.html
https://www.mandiant.com/resources/blog/zero-days-exploited-2022
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.tenable.com/blog/cve-2022-42475-fortinet-patches-zero-day-in-fortios-ssl-vpns