6.7

CVE-2023-40721

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet  allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FortinetFortiOS Version >= 6.2.0 < 7.0.14
FortinetFortiOS Version >= 7.2.0 < 7.2.7
FortinetFortiOS Version7.4.0
FortinetFortiSwitch Manager Version >= 7.0.0 < 7.0.3
FortinetFortiSwitch Manager Version >= 7.2.0 < 7.2.3
FortinetFortiProxy Version >= 1.2.0 < 7.0.15
FortinetFortiProxy Version >= 7.2.0 < 7.2.8
FortinetFortiProxy Version7.4.0
FortinetFortipam Version >= 1.0.0 < 1.2.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.056
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@fortinet.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.