CVE-2023-27997
Summary
| CVE | CVE-2023-27997 |
|---|---|
| State | PUBLISHED |
| Assigner | fortinet |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-13 09:15:16 UTC |
| Updated | 2026-07-31 04:16:43 UTC |
| Description | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.856890000 probability, percentile 0.997040000 (date 2026-08-04)
CISA KEV: Listed on 2023-06-13; due 2023-07-04; ransomware use Known
Problem Types: CWE-122 | CWE-787 | CWE-122 Execute unauthorized code or commands
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.2 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:R |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | Fortinet |
|---|---|
| Product | FortiOS and FortiProxy SSL-VPN |
| Name | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.fortiguard.com/psirt/FG-IR-23-097; https://nvd.nist.gov/vuln/detail/CVE-2023-27997 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Fortinet | FortiOS-6K7K | affected 7.0.10 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 7.0.5 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.4.12 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.4.10 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.4.8 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.4.6 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.4.2 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.2.9 6.2.13 semver | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.2.6 6.2.7 semver | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.2.4 | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.0.12 6.0.16 semver | Not specified |
| CNA | Fortinet | FortiOS-6K7K | affected 6.0.10 | Not specified |
| CNA | Fortinet | FortiProxy | affected 7.2.0 7.2.3 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 7.0.0 7.0.9 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 2.0.0 2.0.12 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 1.2.0 1.2.13 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 1.1.0 1.1.6 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 7.2.0 7.2.4 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 7.0.0 7.0.11 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 6.4.0 6.4.12 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 6.2.0 6.2.13 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 6.0.0 6.0.16 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| PSIRT Advisories | FortiGuard | af854a3a-2127-422b-91ae-364da2661108 | fortiguard.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2023-06-13T00:00:00.000Z | CVE-2023-27997 added to CISA KEV |
Solutions
CNA: Please upgrade to FortiOS-6K7K version 7.0.12 or above Please upgrade to FortiOS-6K7K version 6.4.13 or above Please upgrade to FortiOS-6K7K version 6.2.15 or above Please upgrade to FortiOS-6K7K version 6.0.17 or above Please upgrade to FortiProxy version 7.2.4 or above Please upgrade to FortiProxy version 7.0.10 or above Please upgrade to FortiOS version 7.4.0 or above Please upgrade to FortiOS version 7.2.5 or above Please upgrade to FortiOS version 7.0.12 or above Please upgrade to FortiOS version 6.4.13 or above Please upgrade to FortiOS version 6.2.14 or above Please upgrade to FortiOS version 6.0.17 or above
Legacy QID Mappings
- 44059 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability (FG-IR-23-097)