CVE-2023-46718Stack-based Buffer Overflow in Fortinet Fortios

Severity
7.8HIGHNVD
CNA6.7
EPSS
0.0%
top 94.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDfortinet/fortios7.0.07.2.12+4
CVEListV5fortinet/fortios7.4.07.4.1+5
NVDfortinet/fortiproxy7.0.07.4.8
CVEListV5fortinet/fortiproxy7.4.07.4.7+2

🔴Vulnerability Details

2
CVEList
CVE-2023-46718: A stack-based buffer overflow in Fortinet FortiOS version 72025-10-14
GHSA
GHSA-9fhr-jfxp-p88m: A stack-based buffer overflow in Fortinet FortiOS version 72025-10-14

📋Vendor Advisories

1
Fortinet
Stack-based buffer overflow on fortitoken import feature2025-10-14
CVE-2023-46718 — Stack-based Buffer Overflow | cvebase