CVE-2023-29184
published 2025-06-10CVE-2023-29184: An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM…
PriorityP49low2.3CVSS 3.1
AVLACLPRHUINSUCNILAN
EPSS
0.18%
8.1th percentile
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortios | — | — |
| fortinet | fortios | 6.2.0 – 7.2.11 | — |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.17 | — |
| fortinet | fortios | 7.2.0 – 7.2.11 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 1.1.0 < 7.0.9 | 7.0.9 |
| fortinet | fortiproxy | 1.1.0 – 1.1.6 | — |
| fortinet | fortiproxy | 1.2.0 – 1.2.13 | — |
| fortinet | fortiproxy | 2.0.0 – 2.0.14 | — |
| fortinet | fortiproxy | 7.0.0 – 7.0.8 | — |
| fortinet | fortiproxy | >= 7.2.0 < 7.2.3 | 7.2.3 |
| fortinet | fortiproxy | 7.2.0 – 7.2.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxxf-pxh8-jxxh: An incomplete cleanup vulnerability [CWE-459] in FortiOS 7
ghsa_unreviewed·2025-06-10
CVE-2023-29184 [LOW] CWE-459 GHSA-hxxf-pxh8-jxxh: An incomplete cleanup vulnerability [CWE-459] in FortiOS 7
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
Fortinet
SSH key is added even if operation is aborted
vendor_fortinet·2025-06-10·CVSS 3.2
CVE-2023-29184 [LOW] CWE-459 SSH key is added even if operation is aborted
FG-IR-23-008: SSH key is added even if operation is aborted
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
CVEs: CVE-2023-29184
CWEs: CWE-459
CVSS: 3.2 (low)
Affected products: FortiOS, FortiProxy
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-10
Published