PT-2024-3562 · Fortinet · Fortios

Published

2024-04-09

·

Updated

2025-01-17

·

CVE-2023-48784

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.4.1 and below FortiOS versions 7.2.7 and below FortiOS versions 7.0.14 and below FortiOS versions 6.4.15 and below
Description A use of externally-controlled format string vulnerability in FortiOS command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests. The vulnerability is related to the processing of binary files and the use of uncontrolled format strings.
Recommendations For FortiOS versions 7.4.1 and below, update to a version above 7.4.1. For FortiOS versions 7.2.7 and below, update to a version above 7.2.7. For FortiOS versions 7.0.14 and below, update to a version above 7.0.14. For FortiOS versions 6.4.15 and below, update to a version above 6.4.15. As a temporary workaround, consider restricting CLI access to minimize the risk of exploitation.

Fix

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

BDU:2024-03867
CVE-2023-48784

Affected Products

Fortios