Junglewise Threat Intelligence

CVE-2023-27997: Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

CVE-2023-27997 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-06-13

Technologies: Fortinet FortiProxy, Fortinet FortiProxy SSL-VPN, Fortinet FortiOS, Fortinet FortiADC. Vendors: Fortinet.

Executive brief

A heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiProxy SSL-VPN allows an unauthenticated remote attacker to execute arbitrary code or commands via specifically crafted requests. The vulnerability has been observed being exploited in the wild.

Affected products

  • Fortinet FortiOS 7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below
  • Fortinet FortiProxy 7.2.3 and below, 7.0.9 and below, 2.0.12 and below, 1.2 all versions, 1.1 all versions

Timeline

  • 2023-06-13: disclosed
  • 2023-06-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats