7.2

CVE-2023-45583

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.2, FortiSwitchManager 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiProxy Version < 7.0.12
Fortinet ≫ FortiProxy Version > 7.2.0 < 7.2.6
Fortinet ≫ FortiSwitch Manager Version >= 7.0.0 < 7.0.3
Fortinet ≫ FortiSwitch Manager Version >= 7.2.0 < 7.2.3
Fortinet ≫ FortiOS Version < 7.2.6
Fortinet ≫ FortiOS Version >= 6.2.0 <= 6.2.16
Fortinet ≫ FortiOS Version >= 6.4.0 <= 6.4.15
Fortinet ≫ FortiOS Version >= 7.0.0 <= 7.0.12
Fortinet ≫ FortiOS Version >= 7.2.0 <= 7.2.5
Fortinet ≫ FortiOS Version 7.4.0
Fortinet ≫ Fortipam Version >= 1.0.0 <= 1.0.3
Fortinet ≫ Fortipam Version 1.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.481
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Fortinet 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.