QID 44063
Date Published: 2023-06-29
QID 44063: Fortinet FortiOS Format String Bug Vulnerability (FG-IR-22-463)
A use of externally-controlled format string in Fortinet FortiOS allows attacker to execute unauthorized code or commands via specially crafted commands.
Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 all
FortiOS version 6.4.0 all
FortiOS version 6.2.0 all
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Making this QID practice as this QID also contains banner based detection .
Successful exploit may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-463
Vendor References
- FG-IR-22-463 -
www.fortiguard.com/psirt/FG-IR-22-463
CVEs related to QID 44063
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| https://www.fortiguard.com/psirt/FG-IR-22-463 |
|