PT-2023-3051 · Fortinet · Fortiweb

CVE-2023-25602

·

Publicado

2023-02-16

·

Atualizado

2023-02-27

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiWeb versions 6.4 and earlier FortiWeb versions 6.3.17 and earlier FortiWeb versions 6.2.6 and earlier FortiWeb versions 6.1.2 and earlier FortiWeb versions 6.0.7 and earlier FortiWeb versions 5.9.1 and earlier FortiWeb 5.8 all versions FortiWeb 5.7 all versions FortiWeb 5.6 all versions
Description A stack-based buffer overflow in FortiWeb allows an attacker to execute unauthorized code or commands via specially crafted command arguments. The vulnerability is related to a buffer overflow in memory, which can be exploited by an attacker to execute arbitrary code using specially crafted command arguments.
Recommendations For FortiWeb versions 6.4 and earlier, update to a version that contains a fix for this issue. For FortiWeb versions 6.3.17 and earlier, update to a version that contains a fix for this issue. For FortiWeb versions 6.2.6 and earlier, update to a version that contains a fix for this issue. For FortiWeb versions 6.1.2 and earlier, update to a version that contains a fix for this issue. For FortiWeb versions 6.0.7 and earlier, update to a version that contains a fix for this issue. For FortiWeb versions 5.9.1 and earlier, update to a version that contains a fix for this issue. For FortiWeb 5.8 all versions, update to a version that contains a fix for this issue. For FortiWeb 5.7 all versions, update to a version that contains a fix for this issue. For FortiWeb 5.6 all versions, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of specially crafted command arguments until a patch is available.

Correção

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03118
CVE-2023-25602

Produtos afetados

Fortiweb