Executive brief
A heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiProxy SSL-VPN allows an unauthenticated remote attacker to execute arbitrary code or commands via specifically crafted requests. The vulnerability has been observed being exploited in the wild.
Affected products
- Fortinet FortiOS 7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below
- Fortinet FortiProxy 7.2.3 and below, 7.0.9 and below, 2.0.12 and below, 1.2 all versions, 1.1 all versions
Timeline
- 2023-06-13: disclosed
- 2023-06-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog