Description
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiOS version 7.4.2 or above Please upgrade to FortiOS version 7.2.8 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52817 | A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-413 |
|
History
Fri, 17 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortios |
|
| CPEs | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortios |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T21:37:54.987Z
Reserved: 2023-11-19T19:58:38.554Z
Link: CVE-2023-48784
Updated: 2024-08-02T21:37:54.987Z
Status : Analyzed
Published: 2024-04-09T15:15:28.617
Modified: 2025-01-17T17:19:51.033
Link: CVE-2023-48784
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD