CVE-2023-25610
published 2025-03-24CVE-2023-25610: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through…
PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.80%
96.8th percentile
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Affected
77 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.0.0 < 6.0.12 | 6.0.12 |
| fortinet | fortianalyzer | 6.0.0 – 6.0.11 | — |
| fortinet | fortianalyzer | >= 6.2.0 < 6.2.11 | 6.2.11 |
| fortinet | fortianalyzer | 6.2.0 – 6.2.10 | — |
| fortinet | fortianalyzer | >= 6.4.0 < 6.4.12 | 6.4.12 |
| fortinet | fortianalyzer | 6.4.0 – 6.4.11 | — |
| fortinet | fortianalyzer | >= 7.0.0 < 7.0.5 | 7.0.5 |
| fortinet | fortianalyzer | 7.0.0 – 7.0.4 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.0.0 < 6.0.12 | 6.0.12 |
| fortinet | fortimanager | 6.0.0 – 6.0.11 | — |
| fortinet | fortimanager | >= 6.2.0 < 6.2.11 | 6.2.11 |
| fortinet | fortimanager | 6.2.0 – 6.2.10 | — |
| fortinet | fortimanager | >= 6.4.0 < 6.4.12 | 6.4.12 |
| fortinet | fortimanager | 6.4.0 – 6.4.11 | — |
| fortinet | fortimanager | >= 7.0.0 < 7.0.5 | 7.0.5 |
| fortinet | fortimanager | 7.0.0 – 7.0.4 | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 5.0.0 < 6.2.13 | 6.2.13 |
| fortinet | fortios | 5.0.0 – 5.0.14 | — |
| fortinet | fortios | 5.2.0 – 5.2.15 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the administrative (HTTP/HTTPS) interface of FortiOS/FortiProxy; exploit involves specially crafted requests to the GUI from a remote unauthenticated attacker ↗
- →A public proof-of-concept was published on March 11, 2023 — increase monitoring of FortiOS admin interface traffic from that date onward ↗
- →Exploitation can manifest as either RCE or DoS against the FortiOS/FortiProxy GUI; monitor for unexpected crashes or unresponsiveness of the administrative interface alongside anomalous inbound requests ↗
- →Affected administrative interface is exposed over HTTP and HTTPS; restrict or monitor access to these services on FortiOS/FortiProxy management ports as a detection/mitigation control ↗
- →Vulnerability class is heap buffer underflow (CWE-124) in the administrative interface; look for anomalous memory-corruption-indicative crashes (core dumps, segfaults) in FortiOS/FortiProxy admin processes ↗
- ·FortiOS-6K7K and several other Fortinet products (FortiAnalyzer, FortiManager, FortiSwitch, FortiSwitchManager, FortiWeb) are listed as affected but can only achieve DoS, NOT remote code execution ↗
- ·Affected products span a wide range: FortiOS 6.2–7.2, FortiProxy 1.1–7.2, FortiOS-6K7K, FortiAnalyzer, FortiManager, FortiSwitch, FortiSwitchManager, FortiWeb — ensure detection/patching scope covers all listed product lines ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Heap buffer underflow in administrative interface
vendor_fortinet·2025-03-24·CVSS 9.8
CVE-2023-25610 [CRITICAL] CWE-124 Heap buffer underflow in administrative interface
FG-IR-23-001: Heap buffer underflow in administrative interface
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
CVEs: CVE-2023-25610
CWEs: CWE-124
CVSS: 9.8 (critical)
Affected products: FortiAnalyzer, FortiManager, FortiOS, FortiOs-6k7k, FortiProxy, FortiSwitch, FortiSwitchmanager, FortiWeb, Fortinet
CISA ICS
Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices
cisa_ics·2024-03-14
Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices
ICS Advisory
##
Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices
Release DateMarch 14, 2024
Alert CodeICSA-24-074-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM APE1808 devices
- Vulnerabilities: Improper Certificate Validation, Cleartext Transmission of Sensitive Information, Path Traversal, Exposure of Sensitive Information to an Unauthorized
GHSA
GHSA-wvpr-v2qr-ccvf: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7
ghsa_unreviewed·2025-03-24
CVE-2023-25610 [CRITICAL] CWE-124 GHSA-wvpr-v2qr-ccvf: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
No detection rules found.
No public exploits indexed.
Wiz
RCE meaning: Remote code execution attacks explained | Wiz
blogs_wiz·2026-02-18
RCE meaning: Remote code execution attacks explained | Wiz
## What is a remote code execution (RCE) attack?
A remote code execution (RCE) attack is a cyberattack where an attacker runs malicious code on a target system from a remote location. This means someone who has no physical access to your servers can still execute commands as if they were sitting at the keyboard.
RCE ranks among the most severe vulnerability classes because attackers often need no authentication or user interaction to exploit it. Once they gain code execution, they can steal sensitive data, install persistent backdoors, escalate privileges, or pivot to other systems on your network.
The consequences extend beyond the initial compromise. A single RCE vulnerability in an internet-facing application can give attackers a foothold to move laterally through your environment, e
Wiz
RCE meaning: Remote code execution attacks explained | Wiz
blogs_wiz·2026-02-18
RCE meaning: Remote code execution attacks explained | Wiz
## What is a remote code execution (RCE) attack?
A remote code execution (RCE) attack is a cyberattack where an attacker runs malicious code on a target system from a remote location. This means someone who has no physical access to your servers can still execute commands as if they were sitting at the keyboard.
RCE ranks among the most severe vulnerability classes because attackers often need no authentication or user interaction to exploit it. Once they gain code execution, they can steal sensitive data, install persistent backdoors, escalate privileges, or pivot to other systems on your network.
The consequences extend beyond the initial compromise. A single RCE vulnerability in an internet-facing application can give attackers a foothold to move laterally through your environment, e
Wiz
The First Edition of Crying Out Cloud - The Newsletter! | Wiz
blogs_wiz·2023-04-11·CVSS 6.7
CVE-2023-25610 [MEDIUM] The First Edition of Crying Out Cloud - The Newsletter! | Wiz
The world of cloud security is ever-evolving, and the Wiz Research team is here to keep you updated. This month several impactful vulnerabilities were published, and we observed a few unfortunate security incidents which should be of interest to cloud customers.
Here's a summary of our top picks, enjoy!
## ✨ Highlights
## 🐞 High Profile Vulnerabilities
## Critical RCE vulnerability in Fortinet's FortiOS and FortiProxy
On March 7, Fortinet published an advisory for CVE-2023-25610, a critical buffer underwrite vulnerability in FortiOS. This vulnerability is a bug in the administrative interface which could allow a remote unauthenticated attacker to execute code using specially crafted requests. Based on Wiz data, 7% of cloud enterprise environments are still susceptible to this vulnerab
Wiz
CVE-2023-25610 a critical RCE vulnerability in FortiOS: everything you need to know | Wiz Blog
blogs_wiz·2023-03-13·CVSS 9.8
CVE-2023-25610 [CRITICAL] CVE-2023-25610 a critical RCE vulnerability in FortiOS: everything you need to know | Wiz Blog
On March 7, Fortinet published an advisory for CVE-2023-25610, a critical remote code execution (RCE) vulnerability in FortiOS, Fortinet's operating system. This vulnerability is a buffer underwrite bug in the administrative interface which could allow a remote unauthenticated attacker to execute code using specially crafted requests.
It is highly recommended to upgrade FortiOS instances to the patched versions.
## What is CVE-2023-25610?
The administrative interface for FortiOS and FortiProxy is vulnerable to a buffer underwrite (also known as a "buffer underflow") exploit. A buffer underwrite vulnerability occurs when a program writes data to a buffer (a temporary storage area) with a size that is smaller than the data being written. This can result in the data overwriting adjacent me
Wiz
CVE-2023-25610 a critical RCE vulnerability in FortiOS: everything you need to know | Wiz Blog
blogs_wiz·2023-03-13·CVSS 9.8
CVE-2023-25610 [CRITICAL] CVE-2023-25610 a critical RCE vulnerability in FortiOS: everything you need to know | Wiz Blog
On March 7, Fortinet published an advisory for CVE-2023-25610, a critical remote code execution (RCE) vulnerability in FortiOS, Fortinet's operating system. This vulnerability is a buffer underwrite bug in the administrative interface which could allow a remote unauthenticated attacker to execute code using specially crafted requests.
It is highly recommended to upgrade FortiOS instances to the patched versions.
## What is CVE-2023-25610?
The administrative interface for FortiOS and FortiProxy is vulnerable to a buffer underwrite (also known as a "buffer underflow") exploit. A buffer underwrite vulnerability occurs when a program writes data to a buffer (a temporary storage area) with a size that is smaller than the data being written. This can result in the data overwriting adjacent me
Checkpoint
13th March – Threat Intelligence Report
blogs_checkpoint·2023-03-13
CVE-2023-20049 13th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th March, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Sensitive personal information of more than 56,000 Washington D.C. residents, including an undisclosed number of Senators and members of Congress, has been leaked on a darkweb forum. The leak occurred after the D.C. Health Link marketplace, a health insurance marketplace used by businesses and residents of Washington D.C. was b
2025-03-24
Published