Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25610


A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.


Published

2025-03-24T16:15:17.273

Last Modified

2025-07-24T19:56:34.070

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-124

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiweb < 6.1.4 Yes
Application fortinet fortiweb < 6.2.8 Yes
Application fortinet fortiweb < 6.3.23 Yes
Application fortinet fortiweb < 6.4.3 Yes
Application fortinet fortiweb < 7.0.7 Yes
Application fortinet fortiweb < 7.2.2 Yes
Application fortinet fortiswitchmanager < 7.0.2 Yes
Application fortinet fortiswitchmanager < 7.2.2 Yes
Operating System fortinet fortiswitch < 7.0.7 Yes
Operating System fortinet fortiswitch < 7.2.4 Yes
Application fortinet fortiproxy < 7.0.9 Yes
Application fortinet fortiproxy < 7.2.3 Yes
Application fortinet fortios-6k7k < 6.2.13 Yes
Application fortinet fortios-6k7k < 6.4.12 Yes
Application fortinet fortios-6k7k 7.0.5 Yes
Operating System fortinet fortios < 6.2.13 Yes
Operating System fortinet fortios < 6.4.12 Yes
Operating System fortinet fortios < 7.0.10 Yes
Operating System fortinet fortios < 7.2.4 Yes
Application fortinet fortimanager < 6.0.12 Yes
Application fortinet fortimanager < 6.2.11 Yes
Application fortinet fortimanager < 6.4.12 Yes
Application fortinet fortimanager < 7.0.5 Yes
Application fortinet fortimanager 7.2.0 Yes
Application fortinet fortianalyzer < 6.0.12 Yes
Application fortinet fortianalyzer < 6.2.11 Yes
Application fortinet fortianalyzer < 6.4.12 Yes
Application fortinet fortianalyzer < 7.0.5 Yes
Application fortinet fortianalyzer 7.2.0 Yes

References