Buffer Overflow Vulnerability in Fortinet FortiWeb Web Application Firewall
CVE-2023-25602
7.4HIGH
Summary
A stack-based buffer overflow has been identified in Fortinet FortiWeb web application firewall, allowing attackers to leverage specially crafted command arguments to execute unauthorized code or commands on the affected systems. This vulnerability impacts several versions of FortiWeb and poses a significant risk to the security of web applications. Users are strongly advised to apply the latest updates to mitigate potential exploitation.
Affected Version(s)
FortiWeb 6.4.0 <= 6.4.2
FortiWeb 6.3.0 <= 6.3.17
FortiWeb 6.2.0 <= 6.2.6
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database