7.2

CVE-2023-45584

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiOS Version >= 6.4.0 < 7.0.13
Fortinet ≫ FortiOS Version >= 7.2.0 < 7.2.6
Fortinet ≫ FortiOS Version 7.4.0
Fortinet ≫ Fortipam Version >= 1.0.0 <= 1.1.2
Fortinet ≫ FortiProxy Version >= 7.0.0 < 7.0.14
Fortinet ≫ FortiProxy Version >= 7.2.0 < 7.2.8
Fortinet ≫ FortiProxy Version >= 7.4.0 < 7.4.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.431
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Fortinet 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://fortiguard.fortinet.com/psirt/FG-IR-23-209
Vendor Advisory