PT-2023-1632 · Fortinet · Fortiswitchmanager+5

Published

2023-03-07

·

Updated

2025-03-26

·

CVE-2023-25610

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiOS versions prior to the fixed version FortiProxy versions prior to the fixed version FortiManager versions prior to the fixed version FortiAnalyzer versions prior to the fixed version FortiWeb versions prior to the fixed version FortiSwitchManager versions prior to the fixed version
Description The issue is related to a buffer underwrite vulnerability in the administrative interface of the affected products, which could allow a remote unauthenticated attacker to execute arbitrary code on the device or perform a Denial of Service (DoS) on the GUI. This can be achieved via specifically crafted requests. There are no known instances of this vulnerability being exploited in the wild.
Recommendations For FortiOS, update to a version that includes the security patch for this issue. For FortiProxy, update to a version that includes the security patch for this issue. For FortiManager, update to a version that includes the security patch for this issue. For FortiAnalyzer, update to a version that includes the security patch for this issue. For FortiWeb, update to a version that includes the security patch for this issue. For FortiSwitchManager, update to a version that includes the security patch for this issue. As a temporary workaround, consider restricting access to the administrative interface until a patch is available.

Exploit

Fix

DoS

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01148
CVE-2023-25610

Affected Products

Fortianalyzer
Fortimanager
Fortios
Fortiproxy
Fortiswitchmanager
Fortiweb