VDB

CISA-2023-36640

CISA-2023-36640 PUBLISHED CVSS 6.5 MEDIUM

Reported by fortinet · Published May 14, 2024

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized code or commands via specially crafted commands

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C

Affected Products

VendorProductVersions
FortinetFortiProxy7.2.0, 7.0.0, 2.0.0
FortinetFortiPAM1.0.0
FortinetFortiOS7.2.0, 7.0.0, 6.4.0
fortinetfortiproxy1.0.0, 7.2.0, 1.0.0
FortinetFortiOS7.2.0, 6.0.0, 7.2.0
fortinetfortios7.4.0, 7.2.0, 7.0.0
FortinetFortiPAM1.0.0, 1.0.0
fortinetfortiswitchmanager7.2.0, 7.0.0, 7.2.0
FortinetFortiProxy7.0.0, 2.0.0, 1.2.0
fortinetfortipam1.0.0, 1.0.0

Timeline

  • May 14, 2024 CVE Published
  • Aug 2, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›