QID 44140
Date Published: 2023-12-21
QID 44140: FortiOS Format String Vulnerability (FG-IR-23-138)
A format string vulnerability in the HTTPSd daemon of FortiOS may allow an authenticated user to execute unauthorized code or commands via specially crafted API requests.
Affected Versions:
FortiOS versions 7.2.0 through 7.2.4
FortiOS versions 7.0.0 through 7.0.1
1
FortiOS versions 6.4.0 through 6.4.12
FortiOS versions 6.2.0 through 6.2.15
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable versions of FortiOS may allow an authenticated user to execute unauthorized code or commands via specially crafted API requests.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-138
- FG-IR-23-138 -
www.fortiguard.com/psirt/FG-IR-23-138
CVEs related to QID 44140
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-138 |
|