peter bassill · operator
$ cve CVE-2023-27997 JSON

CVE-2023-27997 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 85.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-07-04.

Description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS85.69% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-122
On CISA KEVyes — remediate by 2023-07-04
Public exploitnone known
Published2023-06-13
Last modified2026-07-31

CISA KEV

NameFortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
Added2023-06-13
Due2023-07-04
Vendor / productFortinet / FortiOS and FortiProxy SSL-VPN
Ransomware useknown

Affected (4)

VendorProduct
fortinetfortigate 6000
fortinetfortigate 7000
fortinetfortios
fortinetfortiproxy

References

→ the Explorer  ·  watch your stack  ·  NVD