PT-2023-3765 · Fortinet · Fortiproxy+1

Published

2023-06-12

·

Updated

2023-06-17

·

CVE-2022-43953

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 6.2 and earlier FortiOS versions 6.4 and earlier FortiOS versions 7.0 and earlier FortiOS versions 7.2.0 through 7.2.4 FortiProxy versions 7.0.0 through 7.0.7 FortiProxy versions 7.2.0 through 7.2.1
Description The issue is related to a use of externally-controlled format string in the command line interpreter of FortiOS and FortiProxy, which may allow an attacker to execute unauthorized code or commands via specially crafted commands or arguments. This could potentially be exploited by an authenticated user.
Recommendations For FortiOS versions 6.2 and earlier, update to a version that is not affected by this issue. For FortiOS versions 6.4 and earlier, update to a version that is not affected by this issue. For FortiOS versions 7.0 and earlier, update to a version that is not affected by this issue. For FortiOS versions 7.2.0 through 7.2.4, update to a version that is not affected by this issue. For FortiProxy versions 7.0.0 through 7.0.7, update to a version that is not affected by this issue. For FortiProxy versions 7.2.0 through 7.2.1, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the command line interpreter until a patch is available.

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04054
CVE-2022-43953

Affected Products

Fortios
Fortiproxy