cbcvebase.
CVE-2023-40721
published 2025-02-11

CVE-2023-40721: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or…

medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios
fortinetfortios>= 6.2.0 < 7.0.147.0.14
fortinetfortios6.2.0 – 6.2.17
fortinetfortios6.4.0 – 6.4.16
fortinetfortios7.0.0 – 7.0.13
fortinetfortios>= 7.2.0 < 7.2.77.2.7
fortinetfortios7.2.0 – 7.2.5
fortinetfortipam
fortinetfortipam>= 1.0.0 < 1.2.01.2.0
fortinetfortipam1.0.0 – 1.0.3
fortinetfortipam1.1.0 – 1.1.2
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy>= 1.2.0 < 7.0.157.0.15
fortinetfortiproxy1.2.0 – 1.2.13
fortinetfortiproxy2.0.0 – 2.0.14
fortinetfortiproxy7.0.0 – 7.0.14
fortinetfortiproxy>= 7.2.0 < 7.2.87.2.8
fortinetfortiproxy7.2.0 – 7.2.6
fortinetfortiswitchmanager
fortinetfortiswitchmanager>= 7.0.0 < 7.0.37.0.3
fortinetfortiswitchmanager7.0.0 – 7.0.2
fortinetfortiswitchmanager>= 7.2.0 < 7.2.37.2.3