CVE-2024-23113
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
- Affected products
- Fortios, Fortipam, Fortiproxy, Fortiswitchmanager
- Fortinet Fortiproxy
- ≤ 7.0.14, 7.2.8, 7.4.2
- Fortinet Fortiswitchmanager
- ≤ 7.0.3, 7.2.3
- Fortinet Fortios
- ≤ 7.0.13, 7.2.6, 7.4.2
- Fortinet Fortipam
- ≤ 1.0.3, 1.1.2, 1.2.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 61.7% (99th percentile)
- Weakness
- CWE-134
- NVD status
- Analyzed
- Published
- 2024-02-15
Fix
Please upgrade to FortiWeb version 7.4.3 or above Please upgrade to FortiVoice version 7.0.2 or above Please upgrade to FortiVoice version 6.4.9 or above Please upgrade to FortiSwitchManager version 7.2.4 or above Please upgrade to FortiSwitchManager version 7.0.4 or above Please upgrade to FortiOS version 7.4.3 or above Please upgrade to FortiOS version 7.2.7 or above Please upgrade to FortiOS version 7.0.14 or above Please upgrade to FortiAuthenticator version 7.0.0 or above Please upgrade to FortiPAM version 1.2.1 or above Please upgrade to FortiPAM version 1.1.3 or above Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.9 or above Please upgrade to FortiProxy version 7.0.16 or above
8 known exploits for CVE-2024-23113
Proof-of-concept code and exploit modules indexed by Sploitus