Buffer Overflow Vulnerability in Fortinet FortiMail and FortiNDR Products
CVE-2023-33302

4.5MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
31 March 2025

Summary

A buffer overflow vulnerability exists in Fortinet's FortiMail webmail and administrative interface, affecting versions 6.4.0 through 6.4.4, and prior to 6.2.6. Additionally, the FortiNDR administrative interface is vulnerable in version 7.2.0 and earlier than 7.1.0. This flaw allows an authenticated attacker with standard webmail access to exploit the vulnerability by sending specially crafted HTTP requests, potentially allowing them to execute unauthorized code or commands.

Affected Version(s)

FortiMail 6.4.0 <= 6.4.4

FortiMail 6.2.0 <= 6.2.6

FortiMail 6.0.0 <= 6.0.10

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.