9.8

CVE-2023-25610

Warning

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
FortinetFortiweb Version >= 6.1.0 < 6.1.4
FortinetFortiweb Version >= 6.2.0 < 6.2.8
FortinetFortiweb Version >= 6.3.0 < 6.3.23
FortinetFortiweb Version >= 6.4.0 < 6.4.3
FortinetFortiweb Version >= 7.0.0 < 7.0.7
FortinetFortiweb Version >= 7.2.0 < 7.2.2
FortinetFortiswitchmanager Version >= 7.0.0 < 7.0.2
FortinetFortiswitchmanager Version >= 7.2.0 < 7.2.2
FortinetFortiswitch Version >= 7.0.0 < 7.0.7
FortinetFortiswitch Version >= 7.2.0 < 7.2.4
FortinetFortiproxy Version >= 1.1.0 < 7.0.9
FortinetFortiproxy Version >= 7.2.0 < 7.2.3
FortinetFortios-6k7k Version >= 6.0.4 < 6.2.13
FortinetFortios-6k7k Version >= 6.4.2 < 6.4.12
FortinetFortios-6k7k Version7.0.5
FortinetFortios Version >= 5.0.0 < 6.2.13
FortinetFortios Version >= 6.4.0 < 6.4.12
FortinetFortios Version >= 7.0.0 < 7.0.10
FortinetFortios Version >= 7.2.0 < 7.2.4
FortinetFortimanager Version >= 6.0.0 < 6.0.12
FortinetFortimanager Version >= 6.2.0 < 6.2.11
FortinetFortimanager Version >= 6.4.0 < 6.4.12
FortinetFortimanager Version >= 7.0.0 < 7.0.5
FortinetFortimanager Version7.2.0
FortinetFortianalyzer Version >= 6.0.0 < 6.0.12
FortinetFortianalyzer Version >= 6.2.0 < 6.2.11
FortinetFortianalyzer Version >= 6.4.0 < 6.4.12
FortinetFortianalyzer Version >= 7.0.0 < 7.0.5
FortinetFortianalyzer Version7.2.0
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 23.08% 0.957
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@fortinet.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-124 Buffer Underwrite ('Buffer Underflow')

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.