9.8
CVE-2023-25610
- EPSS 23.08%
- Published 24.03.2025 15:39:48
- Last modified 24.07.2025 19:56:34
- Source psirt@fortinet.com
- Teams watchlist Login
- Open Login
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Fortinet ≫ Fortiswitchmanager Version >= 7.0.0 < 7.0.2
Fortinet ≫ Fortiswitchmanager Version >= 7.2.0 < 7.2.2
Fortinet ≫ Fortiswitch Version >= 7.0.0 < 7.0.7
Fortinet ≫ Fortiswitch Version >= 7.2.0 < 7.2.4
Fortinet ≫ Fortiproxy Version >= 1.1.0 < 7.0.9
Fortinet ≫ Fortiproxy Version >= 7.2.0 < 7.2.3
Fortinet ≫ Fortios-6k7k Version >= 6.0.4 < 6.2.13
Fortinet ≫ Fortios-6k7k Version >= 6.4.2 < 6.4.12
Fortinet ≫ Fortios-6k7k Version7.0.5
Fortinet ≫ Fortimanager Version >= 6.0.0 < 6.0.12
Fortinet ≫ Fortimanager Version >= 6.2.0 < 6.2.11
Fortinet ≫ Fortimanager Version >= 6.4.0 < 6.4.12
Fortinet ≫ Fortimanager Version >= 7.0.0 < 7.0.5
Fortinet ≫ Fortimanager Version7.2.0
Fortinet ≫ Fortianalyzer Version >= 6.0.0 < 6.0.12
Fortinet ≫ Fortianalyzer Version >= 6.2.0 < 6.2.11
Fortinet ≫ Fortianalyzer Version >= 6.4.0 < 6.4.12
Fortinet ≫ Fortianalyzer Version >= 7.0.0 < 7.0.5
Fortinet ≫ Fortianalyzer Version7.2.0
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 23.08% | 0.957 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@fortinet.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-124 Buffer Underwrite ('Buffer Underflow')
The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.