cbcvebase.
CVE-2023-42789
published 2024-03-12

CVE-2023-42789: A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.28%
87.0th percentile
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

Affected

15 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios
fortinetfortios
fortinetfortios6.2.0 – 6.2.15
fortinetfortios6.4.0 – 6.4.14
fortinetfortios7.0.0 – 7.0.12
fortinetfortios7.2.0 – 7.2.5
fortinetfortios7.4.0 – 7.4.1
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy2.0.0 – 2.0.13
fortinetfortiproxy7.0.0 – 7.0.12
fortinetfortiproxy7.2.0 – 7.2.6
fortinetfortisase

Detection & IOCsextracted from sources · hover to see the quote

  • Two vulnerability classes are present: out-of-bounds write (CWE-787) and stack-based buffer overflow (CWE-121) — detection rules should cover both memory corruption patterns in HTTP request handling on the captive portal
  • CVSS score is 9.8 (critical) and the vulnerability is pre-authentication (captive portal is externally accessible); prioritize detection on internet-facing FortiOS/FortiProxy management or captive portal interfaces
  • ·Affected FortiOS versions span a wide range (6.2.x through 7.4.1); ensure version fingerprinting covers all branches when scoping detection or patching
  • ·Both CVE-2023-42789 (out-of-bounds write) and CVE-2023-42790 (stack-based buffer overflow) affect the same captive portal component and the same product/version matrix; treat them together in patch and detection planning
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.