cbcvebase.
CVE-2024-23113
published 2024-02-15

CVE-2024-23113: A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-30
Exploited in the wild
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

Affected

16 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios7.0.0 – 7.0.13
fortinetfortios7.2.0 – 7.2.6
fortinetfortios7.4.0 – 7.4.2
fortinetfortipam
fortinetfortipam
fortinetfortipam1.0.0 – 1.0.3
fortinetfortipam1.1.0 – 1.1.2
fortinetfortiproxy
fortinetfortiproxy7.0.0 – 7.0.14
fortinetfortiproxy7.2.0 – 7.2.8
fortinetfortiproxy7.4.0 – 7.4.2
fortinetfortiswitchmanager
fortinetfortiswitchmanager7.0.0 – 7.0.3
fortinetfortiswitchmanager7.2.0 – 7.2.3

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL