QID 44067
Date Published: 2023-06-21
QID 44067: Fortinet FortiOS Privilege Escalation Vulnerability (FG-IR-22-494)
An out-of-bounds write vulnerability [CWE-787] in Command Line Interface of FortiOS and FortiProxy may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted commands.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.10
FortiOS version 6.4.0 through 6.4.12
FortiOS 6.2 all versions
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of this vulnerability may allow an attacker to escalation of privilege via specifically crafted commands.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-494
Vendor References
- FG-IR-22-494 -
www.fortiguard.com/psirt/FG-IR-22-494
CVEs related to QID 44067
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-494 |
|