CVE-2023-45584
EUVD-2023-4987612.08.2025, 19:15
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortios | 6.4.0 ≤ 𝑥 < 7.0.13 |
| fortinet | fortios | 7.2.0 ≤ 𝑥 < 7.2.6 |
| fortinet | fortios | 7.4.0 |
| fortinet | fortipam | 1.0.0 ≤ 𝑥 ≤ 1.1.2 |
| fortinet | fortiproxy | 7.0.0 ≤ 𝑥 < 7.0.14 |
| fortinet | fortiproxy | 7.2.0 ≤ 𝑥 < 7.2.8 |
| fortinet | fortiproxy | 7.4.0 ≤ 𝑥 < 7.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration