PT-2024-3560 · Fortinet · Fortiswitchmanager+3
Published
2024-05-14
·
Updated
2024-05-23
·
CVE-2023-45583
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiProxy versions 1.1.0 through 1.2.13
FortiProxy versions 2.0.0 through 2.0.13
FortiProxy versions 7.0.0 through 7.2.5
FortiPAM versions 1.0.0 through 1.1.0
FortiOS versions 6.2.0 through 7.4.0
FortiSwitchManager versions 7.0.0 through 7.2.2
Description
The issue is related to the use of externally-controlled format strings in the command line interpreter and httpd of FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager. This allows an attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.
Recommendations
For FortiProxy versions 1.1.0 through 1.2.13, update to a version outside of the affected range.
For FortiProxy versions 2.0.0 through 2.0.13, update to a version outside of the affected range.
For FortiProxy versions 7.0.0 through 7.2.5, update to a version outside of the affected range.
For FortiPAM versions 1.0.0 through 1.1.0, update to a version outside of the affected range.
For FortiOS versions 6.2.0 through 7.4.0, update to a version outside of the affected range.
For FortiSwitchManager versions 7.0.0 through 7.2.2, update to a version outside of the affected range.
As a temporary workaround, consider restricting access to the command line interpreter and httpd to minimize the risk of exploitation.
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios
Fortipam
Fortiproxy
Fortiswitchmanager