PT-2025-13782 · Fortinet · Fortimail+1
Published
2025-03-31
·
Updated
2025-07-23
·
CVE-2023-33302
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiMail versions 6.4.0 through 6.4.4
FortiMail versions prior to 6.2.6
FortiNDR versions prior to 7.1.0
FortiNDR version 7.2.0
Description
A buffer copy without checking the size of input, also known as a 'classic buffer overflow', allows an authenticated attacker with regular webmail access to trigger a buffer overflow. This could lead to the execution of unauthorized code or commands via specifically crafted HTTP requests.
Recommendations
For FortiMail versions 6.4.0 through 6.4.4, update to a version outside of this range to mitigate the risk.
For FortiMail versions prior to 6.2.6, update to version 6.2.6 or later.
For FortiNDR versions prior to 7.1.0, update to version 7.1.0 or later.
For FortiNDR version 7.2.0, consider disabling access to the administrative interface until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortimail
Fortindr