CVE-2022-43953Use of Externally-Controlled Format String in Fortinet Fortios

Severity
7.8HIGHNVD
CNA6.7
EPSS
0.0%
top 85.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13

Description

A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via specially crafted commands.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5fortinet/fortios7.2.07.2.4+3
NVDfortinet/fortios6.2.06.2.15+3
CVEListV5fortinet/fortiproxy7.2.07.2.1+1
NVDfortinet/fortiproxy7.0.07.0.7+2

🔴Vulnerability Details

2
CVEList
CVE-2022-43953: A use of externally-controlled format string in Fortinet FortiOS version 72023-06-13
GHSA
GHSA-vv6m-9gcj-8cf5: A use of externally-controlled format string in Fortinet FortiOS version 72023-06-13

📋Vendor Advisories

1
Fortinet
Format String Bug in fortiguard-resources CLI command2023-06-13
CVE-2022-43953 — Fortinet Fortios vulnerability | cvebase