PT-2024-3562 · Fortinet · Fortios
Published
2024-04-09
·
Updated
2025-01-17
·
CVE-2023-48784
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 7.4.1 and below
FortiOS versions 7.2.7 and below
FortiOS versions 7.0.14 and below
FortiOS versions 6.4.15 and below
Description
A use of externally-controlled format string vulnerability in FortiOS command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests. The vulnerability is related to the processing of binary files and the use of uncontrolled format strings.
Recommendations
For FortiOS versions 7.4.1 and below, update to a version above 7.4.1.
For FortiOS versions 7.2.7 and below, update to a version above 7.2.7.
For FortiOS versions 7.0.14 and below, update to a version above 7.0.14.
For FortiOS versions 6.4.15 and below, update to a version above 6.4.15.
As a temporary workaround, consider restricting CLI access to minimize the risk of exploitation.
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios