imPC@ndo IT

Tracker / CVE-2023-25610

CVE-2023-25610

Critical 9.8

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Affected products and versions

fortinet fortianalyzer
fortinet fortianalyzer · 6.0.0 → 6.0.12
fortinet fortianalyzer · 6.2.0 → 6.2.11
fortinet fortianalyzer · 6.4.0 → 6.4.12
fortinet fortianalyzer · 7.0.0 → 7.0.5
fortinet fortimanager
fortinet fortimanager · 6.0.0 → 6.0.12
fortinet fortimanager · 6.2.0 → 6.2.11
fortinet fortimanager · 6.4.0 → 6.4.12
fortinet fortimanager · 7.0.0 → 7.0.5
fortinet fortios · 5.0.0 → 6.2.13
fortinet fortios · 6.4.0 → 6.4.12
fortinet fortios · 7.0.0 → 7.0.10
fortinet fortios · 7.2.0 → 7.2.4
fortinet fortios-6k7k
fortinet fortios-6k7k · 6.0.4 → 6.2.13
fortinet fortios-6k7k · 6.4.2 → 6.4.12
fortinet fortiproxy · 1.1.0 → 7.0.9
fortinet fortiproxy · 7.2.0 → 7.2.3
fortinet fortiswitch · 7.0.0 → 7.0.7
fortinet fortiswitch · 7.2.0 → 7.2.4
fortinet fortiswitchmanager · 7.0.0 → 7.0.2
fortinet fortiswitchmanager · 7.2.0 → 7.2.2
fortinet fortiweb · 6.1.0 → 6.1.4
fortinet fortiweb · 6.2.0 → 6.2.8
fortinet fortiweb · 6.3.0 → 6.3.23
fortinet fortiweb · 6.4.0 → 6.4.3
fortinet fortiweb · 7.0.0 → 7.0.7
fortinet fortiweb · 7.2.0 → 7.2.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References