CVE-2023-46720Stack-based Buffer Overflow in Fortinet Fortios

Severity
7.8HIGHNVD
CNA6.7
EPSS
0.1%
top 79.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11

Description

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortios7.2.07.2.8+5
CVEListV5fortinet/fortios7.4.07.4.1+5

🔴Vulnerability Details

2
CVEList
CVE-2023-46720: A stack-based buffer overflow in Fortinet FortiOS version 72024-06-11
GHSA
GHSA-6v98-q8cq-9rx2: A stack-based buffer overflow in Fortinet FortiOS version 72024-06-11

📋Vendor Advisories

1
Fortinet
Stack buffer overflow on bluetooth write feature2024-06-11
CVE-2023-46720 — Stack-based Buffer Overflow | cvebase