PT-2023-7379 · Fortinet · Fortiddos-F+1
Published
2023-11-14
·
Updated
2023-11-21
·
CVE-2023-29177
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiADC versions 7.2.0 and prior to 7.1.2
FortiDDoS-F versions 6.5.0 and prior to 6.4.1
Description
The issue is related to multiple buffer copy without checking the size of input, which is a 'classic buffer overflow' vulnerability. This allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI requests.
Recommendations
For FortiADC versions 7.2.0 and prior to 7.1.2, update to a version that includes the fix for this issue.
For FortiDDoS-F versions 6.5.0 and prior to 6.4.1, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the CLI to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiadc
Fortiddos-F