Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27997


A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.


Published

2023-06-13T09:15:16.613

Last Modified

2025-03-10T20:40:57.323

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-122
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiproxy ≤ 1.1.6 Yes
Application fortinet fortiproxy ≤ 1.2.13 Yes
Application fortinet fortiproxy ≤ 2.0.12 Yes
Application fortinet fortiproxy ≤ 7.0.9 Yes
Application fortinet fortiproxy ≤ 7.2.3 Yes
Operating System fortinet fortios ≤ 6.0.16 Yes
Operating System fortinet fortios ≤ 6.2.13 Yes
Operating System fortinet fortios ≤ 6.4.12 Yes
Operating System fortinet fortios ≤ 7.0.11 Yes
Operating System fortinet fortios ≤ 7.2.4 Yes
Operating System fortinet fortios ≤ 6.0.16 Yes
Operating System fortinet fortios ≤ 6.2.13 Yes
Operating System fortinet fortios 6.0.10 Yes
Operating System fortinet fortios 6.2.4 Yes
Operating System fortinet fortios 6.2.6 Yes
Operating System fortinet fortios 6.2.7 Yes
Operating System fortinet fortios 6.4.2 Yes
Operating System fortinet fortios 6.4.6 Yes
Operating System fortinet fortios 6.4.8 Yes
Operating System fortinet fortios 6.4.10 Yes
Operating System fortinet fortios 6.4.12 Yes
Operating System fortinet fortios 7.0.5 Yes
Operating System fortinet fortios 7.0.10 Yes
Hardware fortinet fortigate_6000 - No
Hardware fortinet fortigate_7000 - No

References