CVE-2023-42790Stack-based Buffer Overflow in Fortinet Fortios

Severity
8.1HIGHNVD
EPSS
0.1%
top 67.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12

Description

A stack-based buffer overflow in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

CVEListV5fortinet/fortios7.4.07.4.1+4
NVDfortinet/fortios6.2.06.2.15+4
CVEListV5fortinet/fortiproxy7.2.07.2.6+3
NVDfortinet/fortiproxy2.0.02.0.13+3

🔴Vulnerability Details

2
GHSA
GHSA-jcfw-h88c-w44g: A stack-based buffer overflow in Fortinet FortiOS 72024-03-12
CVEList
CVE-2023-42790: A stack-based buffer overflow in Fortinet FortiOS 72024-03-12

📋Vendor Advisories

1
Fortinet
Out-of-bounds Write in captive portal2024-03-12
CVE-2023-42790 — Stack-based Buffer Overflow | cvebase