9.8

CVE-2023-25610

Warnung
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortiweb Version >= 6.1.0 < 6.1.4
Fortinet ≫ Fortiweb Version >= 6.2.0 < 6.2.8
Fortinet ≫ Fortiweb Version >= 6.3.0 < 6.3.23
Fortinet ≫ Fortiweb Version >= 6.4.0 < 6.4.3
Fortinet ≫ Fortiweb Version >= 7.0.0 < 7.0.7
Fortinet ≫ Fortiweb Version >= 7.2.0 < 7.2.2
Fortinet ≫ FortiSwitch Manager Version >= 7.0.0 < 7.0.2
Fortinet ≫ FortiSwitch Manager Version >= 7.2.0 < 7.2.2
Fortinet ≫ Fortiswitch Version >= 7.0.0 < 7.0.7
Fortinet ≫ Fortiswitch Version >= 7.2.0 < 7.2.4
Fortinet ≫ FortiProxy Version >= 1.1.0 < 7.0.9
Fortinet ≫ FortiProxy Version >= 7.2.0 < 7.2.3
Fortinet ≫ Fortios-6k7k Version >= 6.0.4 < 6.2.13
Fortinet ≫ Fortios-6k7k Version >= 6.4.2 < 6.4.12
Fortinet ≫ Fortios-6k7k Version 7.0.5
Fortinet ≫ FortiOS Version >= 5.0.0 < 6.2.13
Fortinet ≫ FortiOS Version >= 6.4.0 < 6.4.12
Fortinet ≫ FortiOS Version >= 7.0.0 < 7.0.10
Fortinet ≫ FortiOS Version >= 7.2.0 < 7.2.4
Fortinet ≫ Fortimanager Version >= 6.0.0 < 6.0.12
Fortinet ≫ Fortimanager Version >= 6.2.0 < 6.2.11
Fortinet ≫ Fortimanager Version >= 6.4.0 < 6.4.12
Fortinet ≫ Fortimanager Version >= 7.0.0 < 7.0.5
Fortinet ≫ Fortimanager Version 7.2.0
Fortinet ≫ Fortianalyzer Version >= 6.0.0 < 6.0.12
Fortinet ≫ Fortianalyzer Version >= 6.2.0 < 6.2.11
Fortinet ≫ Fortianalyzer Version >= 6.4.0 < 6.4.12
Fortinet ≫ Fortianalyzer Version >= 7.0.0 < 7.0.5
Fortinet ≫ Fortianalyzer Version 7.2.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.18% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Fortinet 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-124 Buffer Underwrite ('Buffer Underflow')

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.