CVE-2023-25610

EUVD-2023-29551
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Buffer Underflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
9.3 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
fortinetfortiweb
6.1.0 ≤
𝑥
< 6.1.4
fortinetfortiweb
6.2.0 ≤
𝑥
< 6.2.8
fortinetfortiweb
6.3.0 ≤
𝑥
< 6.3.23
fortinetfortiweb
6.4.0 ≤
𝑥
< 6.4.3
fortinetfortiweb
7.0.0 ≤
𝑥
< 7.0.7
fortinetfortiweb
7.2.0 ≤
𝑥
< 7.2.2
fortinetfortiswitchmanager
7.0.0 ≤
𝑥
< 7.0.2
fortinetfortiswitchmanager
7.2.0 ≤
𝑥
< 7.2.2
fortinetfortiswitch
7.0.0 ≤
𝑥
< 7.0.7
fortinetfortiswitch
7.2.0 ≤
𝑥
< 7.2.4
fortinetfortiproxy
1.1.0 ≤
𝑥
< 7.0.9
fortinetfortiproxy
7.2.0 ≤
𝑥
< 7.2.3
fortinetfortios-6k7k
6.0.4 ≤
𝑥
< 6.2.13
fortinetfortios-6k7k
6.4.2 ≤
𝑥
< 6.4.12
fortinetfortios-6k7k
7.0.5
fortinetfortios
5.0.0 ≤
𝑥
< 6.2.13
fortinetfortios
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.10
fortinetfortios
7.2.0 ≤
𝑥
< 7.2.4
fortinetfortimanager
6.0.0 ≤
𝑥
< 6.0.12
fortinetfortimanager
6.2.0 ≤
𝑥
< 6.2.11
fortinetfortimanager
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortimanager
7.0.0 ≤
𝑥
< 7.0.5
fortinetfortimanager
7.2.0
fortinetfortianalyzer
6.0.0 ≤
𝑥
< 6.0.12
fortinetfortianalyzer
6.2.0 ≤
𝑥
< 6.2.11
fortinetfortianalyzer
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortianalyzer
7.0.0 ≤
𝑥
< 7.0.5
fortinetfortianalyzer
7.2.0
𝑥
= Vulnerable software versions