PT-2024-3559 · Fortinet · Fortios

Published

2024-05-14

·

Updated

2024-06-19

·

CVE-2023-46714

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.2.1 through 7.2.6 FortiOS versions 7.4.0 through 7.4.1
Description The issue is related to a stack-based buffer overflow that may allow a privileged attacker to execute arbitrary code or commands via crafted HTTP or HTTPS requests. This can be done by sending specially formed requests to the administrative interface.
Recommendations For FortiOS versions 7.2.1 through 7.2.6, update to a version outside of this range to resolve the issue. For FortiOS versions 7.4.0 through 7.4.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the administrative interface to minimize the risk of exploitation.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03864
CVE-2023-46714

Affected Products

Fortios