8.8

CVE-2023-41678

A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiOS Version 7.0.0
Fortinet ≫ FortiOS Version 7.0.1
Fortinet ≫ FortiOS Version 7.0.2
Fortinet ≫ FortiOS Version 7.0.3
Fortinet ≫ FortiOS Version 7.0.4
Fortinet ≫ FortiOS Version 7.0.5
Fortinet ≫ Fortipam Version 1.0.0
Fortinet ≫ Fortipam Version 1.0.1
Fortinet ≫ Fortipam Version 1.0.2
Fortinet ≫ Fortipam Version 1.0.3
Fortinet ≫ Fortipam Version 1.1.0
Fortinet ≫ Fortipam Version 1.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.07% 0.604
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Fortinet 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.