QID 44031
Date Published: 2023-05-29
QID 44031: Fortinet FortiOS Arbitrary Code Execution (ACE) Vulnerability (FG-IR-22-475)
An out-of-bounds write vulnerability [CWE-787] in sslvpnd of FortiOS and FortiProxy may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted requests.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.10
FortiOS version 6.4.0 through 6.4.11
FortiOS version 6.2.0 through 6.2.13
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted requests
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-475
Vendor References
- FG-IR-22-475 -
www.fortiguard.com/psirt/FG-IR-22-475
CVEs related to QID 44031
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-475 |
|