cbcvebase.
CVE-2023-25610
published 2025-03-24

CVE-2023-25610: A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through…

PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.80%
96.8th percentile
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Affected

77 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer>= 6.0.0 < 6.0.126.0.12
fortinetfortianalyzer6.0.0 – 6.0.11
fortinetfortianalyzer>= 6.2.0 < 6.2.116.2.11
fortinetfortianalyzer6.2.0 – 6.2.10
fortinetfortianalyzer>= 6.4.0 < 6.4.126.4.12
fortinetfortianalyzer6.4.0 – 6.4.11
fortinetfortianalyzer>= 7.0.0 < 7.0.57.0.5
fortinetfortianalyzer7.0.0 – 7.0.4
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager>= 6.0.0 < 6.0.126.0.12
fortinetfortimanager6.0.0 – 6.0.11
fortinetfortimanager>= 6.2.0 < 6.2.116.2.11
fortinetfortimanager6.2.0 – 6.2.10
fortinetfortimanager>= 6.4.0 < 6.4.126.4.12
fortinetfortimanager6.4.0 – 6.4.11
fortinetfortimanager>= 7.0.0 < 7.0.57.0.5
fortinetfortimanager7.0.0 – 7.0.4
fortinetfortinet
fortinetfortios
fortinetfortios>= 5.0.0 < 6.2.136.2.13
fortinetfortios5.0.0 – 5.0.14
fortinetfortios5.2.0 – 5.2.15

Detection & IOCsextracted from sources · hover to see the quote

  • Target the administrative (HTTP/HTTPS) interface of FortiOS/FortiProxy; exploit involves specially crafted requests to the GUI from a remote unauthenticated attacker
  • A public proof-of-concept was published on March 11, 2023 — increase monitoring of FortiOS admin interface traffic from that date onward
  • Exploitation can manifest as either RCE or DoS against the FortiOS/FortiProxy GUI; monitor for unexpected crashes or unresponsiveness of the administrative interface alongside anomalous inbound requests
  • Affected administrative interface is exposed over HTTP and HTTPS; restrict or monitor access to these services on FortiOS/FortiProxy management ports as a detection/mitigation control
  • Vulnerability class is heap buffer underflow (CWE-124) in the administrative interface; look for anomalous memory-corruption-indicative crashes (core dumps, segfaults) in FortiOS/FortiProxy admin processes
  • ·FortiOS-6K7K and several other Fortinet products (FortiAnalyzer, FortiManager, FortiSwitch, FortiSwitchManager, FortiWeb) are listed as affected but can only achieve DoS, NOT remote code execution
  • ·Affected products span a wide range: FortiOS 6.2–7.2, FortiProxy 1.1–7.2, FortiOS-6K7K, FortiAnalyzer, FortiManager, FortiSwitch, FortiSwitchManager, FortiWeb — ensure detection/patching scope covers all listed product lines
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.