QID 44083

Date Published: 2023-07-13

QID 44083: FortiOS - Stack-based Buffer Overflow Vulnerability (FG-IR-23-183)

FortiOS is vulnerable to a stack-based overflow vulnerability.

Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.10

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Note: Making this QID practice as this QID also contains banner based detection .

Vulnerable versions of FortiOS may allow a remote attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-23-183
    Vendor References

    CVEs related to QID 44083

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-183 URL Logo www.fortiguard.com/psirt/FG-IR-23-183