CVE-2023-46714
published 2024-05-14CVE-2023-46714: A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged…
PriorityP349high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.40%
69.3th percentile
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 7.2.1 – 7.2.6 | — |
| fortinet | fortios | 7.4.0 – 7.4.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Buffer overflow in administrative interface
vendor_fortinet·2024-05-14·CVSS 7.2
CVE-2023-46714 [HIGH] CWE-121 Buffer overflow in administrative interface
FG-IR-23-415: Buffer overflow in administrative interface
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.
CVEs: CVE-2023-46714
CWEs: CWE-121
CVSS: 7.2 (high)
Affected products: FortiOS, Fortinet
GHSA
GHSA-43hj-8x3j-rc7x: A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7
ghsa_unreviewed·2024-05-14
CVE-2023-46714 [HIGH] CWE-121 GHSA-43hj-8x3j-rc7x: A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-14
Published