Buffer Overflow Vulnerability in Fortinet FortiMail and FortiNDR Products
CVE-2023-33302
4.5MEDIUM
What is CVE-2023-33302?
A buffer overflow vulnerability exists in Fortinet's FortiMail webmail and administrative interface, affecting versions 6.4.0 through 6.4.4, and prior to 6.2.6. Additionally, the FortiNDR administrative interface is vulnerable in version 7.2.0 and earlier than 7.1.0. This flaw allows an authenticated attacker with standard webmail access to exploit the vulnerability by sending specially crafted HTTP requests, potentially allowing them to execute unauthorized code or commands.
Affected Version(s)
FortiMail 6.4.0 <= 6.4.4
FortiMail 6.2.0 <= 6.2.6
FortiMail 6.0.0 <= 6.0.10