QID 44136

Date Published: 2023-11-29

QID 44136: FortiOS Multiple Vulnerabilities (FG-IR-23-385)

CVE-2023-38545:
A heap-based buffer overflow flaw was found in the SOCKS5 proxy handshake in the Curl package.s.
CVE-2023-38546:
A flaw was found in the Curl package. This flaw allows an attacker to insert cookies into a running program using libcurl if the specific series of conditions are met.

Affected Products:
The following products are impacted: FortiGate (Only FGT_VM64 model is impacted and authentication is required) FGT_VM64 version 7.4.0 through 7.4.1 FGT_VM64 version 7.2.0 through 7.2.6 FGT_VM64 version 7.0.1 through 7.0.13

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-23-385

    Vendor References

    CVEs related to QID 44136

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-385 URL Logo www.fortiguard.com/psirt/FG-IR-23-385