CVE-2023-29182
published 2023-08-17CVE-2023-29182: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially…
PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.25%
16.7th percentile
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.2.0 < 7.0.4 | 7.0.4 |
| fortinet | fortios | 6.2.0 – 6.2.15 | — |
| fortinet | fortios | 6.4.0 – 6.4.14 | — |
| fortinet | fortios | 7.0.0 – 7.0.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qf45-v3jg-6772: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7
ghsa_unreviewed·2023-08-17
CVE-2023-29182 [MEDIUM] CWE-121 GHSA-qf45-v3jg-6772: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.
Fortinet
Buffer overflow in execute extender command
vendor_fortinet·2023-08-17·CVSS 6.4
CVE-2023-29182 [MEDIUM] CWE-121 Buffer overflow in execute extender command
FG-IR-23-149: Buffer overflow in execute extender command
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.
CVEs: CVE-2023-29182
CWEs: CWE-121, CWE-787
CVSS: 6.4 (medium)
Affected products: FortiOS, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-17
Published