← All CVEs

CVE-2023-27997

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2023-06-13Remediation due 2023-07-04

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

9.8
CVSS
85.7%
EPSS (exploit prob.)
100th
EPSS percentile
2023-06-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122CWE-787

Affected products

VendorProductAffected versions
fortinetfortiproxy>= 1.1.0, <= 1.1.6
fortinetfortiproxy>= 1.2.0, <= 1.2.13
fortinetfortiproxy>= 2.0.0, <= 2.0.12
fortinetfortiproxy>= 7.0.0, <= 7.0.9
fortinetfortiproxy>= 7.2.0, <= 7.2.3
fortinetfortios>= 6.0.0, <= 6.0.16
fortinetfortios>= 6.2.0, <= 6.2.13
fortinetfortios>= 6.4.0, <= 6.4.12
fortinetfortios>= 7.0.0, <= 7.0.11
fortinetfortios>= 7.2.0, <= 7.2.4
fortinetfortios>= 6.0.12, <= 6.0.16
fortinetfortios>= 6.2.9, <= 6.2.13
fortinetfortios6.0.10
fortinetfortios6.2.4
fortinetfortios6.2.6
fortinetfortios6.2.7
fortinetfortios6.4.2
fortinetfortios6.4.6
fortinetfortios6.4.8
fortinetfortios6.4.10
fortinetfortios6.4.12
fortinetfortios7.0.5
fortinetfortios7.0.10
fortinetfortigate_6000all versions
fortinetfortigate_7000all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-27997