A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
2023-01-02T09:15:09.490
2025-02-24T15:44:21.153
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fortinet | fortios | ≤ 5.0.14 | Yes |
Operating System | fortinet | fortios | ≤ 5.2.15 | Yes |
Operating System | fortinet | fortios | ≤ 5.4.13 | Yes |
Operating System | fortinet | fortios | ≤ 5.6.14 | Yes |
Operating System | fortinet | fortios | < 6.0.16 | Yes |
Operating System | fortinet | fortios | < 6.2.12 | Yes |
Operating System | fortinet | fortios | < 6.4.11 | Yes |
Operating System | fortinet | fortios | < 7.0.9 | Yes |
Operating System | fortinet | fortios | < 7.2.3 | Yes |
Application | fortinet | fortiproxy | ≤ 1.0.7 | Yes |
Application | fortinet | fortiproxy | ≤ 1.1.6 | Yes |
Application | fortinet | fortiproxy | ≤ 1.2.13 | Yes |
Application | fortinet | fortiproxy | < 2.0.12 | Yes |
Application | fortinet | fortiproxy | < 7.0.8 | Yes |
Application | fortinet | fortiproxy | < 7.2.2 | Yes |
Operating System | fortinet | fortios | < 6.0.15 | Yes |
Operating System | fortinet | fortios | < 6.2.12 | Yes |
Operating System | fortinet | fortios | < 6.4.10 | Yes |
Operating System | fortinet | fortios | < 7.0.8 | Yes |
Hardware | fortinet | fim-7901e | - | No |
Hardware | fortinet | fim-7904e | - | No |
Hardware | fortinet | fim-7910e | - | No |
Hardware | fortinet | fim-7920e | - | No |
Hardware | fortinet | fim-7921f | - | No |
Hardware | fortinet | fim-7941f | - | No |
Hardware | fortinet | fortigate-6300f | - | No |
Hardware | fortinet | fortigate-6300f-dc | - | No |
Hardware | fortinet | fortigate-6500f | - | No |
Hardware | fortinet | fortigate-6500f-dc | - | No |
Hardware | fortinet | fortigate-6501f | - | No |
Hardware | fortinet | fortigate-6501f-dc | - | No |
Hardware | fortinet | fortigate-6601f | - | No |
Hardware | fortinet | fortigate-6601f-dc | - | No |
Hardware | fortinet | fortigate-7030e | - | No |
Hardware | fortinet | fortigate-7040e | - | No |
Hardware | fortinet | fortigate-7060e | - | No |
Hardware | fortinet | fortigate-7121f | - | No |
Hardware | fortinet | fpm-7620e | - | No |
Hardware | fortinet | fpm-7620f | - | No |
Hardware | fortinet | fpm-7630e | - | No |