Format String Vulnerability in Fortinet FortiProxy and FortiOS Products
CVE-2023-45583
7.2HIGH
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 14 May 2024
What is CVE-2023-45583?
A format string vulnerability exists in certain versions of Fortinet's FortiProxy, FortiOS, and FortiSwitchManager products due to inadequate validation of external input. This weakness allows an attacker to execute arbitrary code or commands by crafting specific command-line interface (CLI) commands and HTTP requests. The vulnerability impacts multiple versions across various Fortinet products, consequently posing a significant risk to affected systems.
Affected Version(s)
FortiOS 7.4.0
FortiOS 7.2.0 <= 7.2.5
FortiOS 7.0.0 <= 7.0.12