Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
Summary
| CVE | CVE-2023-27997 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-13 09:15:00 UTC |
| Updated | 2023-11-07 04:10:00 UTC |
| Description | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests. |
Risk And Classification
EPSS: 0.903510000 probability, percentile 0.996020000 (date 2026-04-05)
CISA KEV: Listed on 2023-06-13; due 2023-07-04; ransomware use Known
Problem Types: CWE-787
CISA Known Exploited Vulnerability
| Vendor | Fortinet |
|---|---|
| Product | FortiOS and FortiProxy SSL-VPN |
| Name | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.fortiguard.com/psirt/FG-IR-23-097; https://nvd.nist.gov/vuln/detail/CVE-2023-27997 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.0.10 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.0.12 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.0.13 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.0.14 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.0.15 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.0.16 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.2.4 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.2.6 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.2.7 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.2.9 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.4.10 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.4.12 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.4.2 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.4.6 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 6.4.8 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 7.0.10 | All | All | All |
| Application | Fortinet | Fortios-6k7k | 7.0.5 | All | All | All |
| Application | Fortinet | Fortios-6k7k | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PSIRT Advisories | FortiGuard | MISC | fortiguard.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 44059 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability (FG-IR-23-097)