CVE-2024-23113

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8,

Severity
Critical 9.8
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Oct 9, 2024
EPSS
0.617
99.1th percentile
Discovered by
Not disclosed
Published
Feb 15, 2024
Assigned by fortinet

Description

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

Weakness: CWE-134

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy SASE / SSE / Secure Web cna-assigner
Fortinet FortiSwitch Routing & Switching cna-assigner
Vendor-reported affected versions (15)
  • Fortinet · FortiSwitchManager
  • Fortinet · FortiOS
  • Fortinet · FortiPAM
  • Fortinet · FortiProxy
  • fortinet · fortiswitchmanager
  • fortinet · fortiswitchmanager
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortios
  • fortinet · fortiproxy
  • fortinet · fortiproxy
  • fortinet · fortiproxy
  • fortinet · fortipam
  • fortinet · fortipam
  • fortinet · fortipam

Vendor remediation

Please upgrade to FortiWeb version 7.4.3 or above Please upgrade to FortiVoice version 7.0.2 or above Please upgrade to FortiVoice version 6.4.9 or above Please upgrade to FortiSwitchManager version 7.2.4 or above Please upgrade to FortiSwitchManager version 7.0.4 or above Please upgrade to FortiOS version 7.4.3 or above Please upgrade to FortiOS version 7.2.7 or above Please upgrade to FortiOS version 7.0.14 or above Please upgrade to FortiAuthenticator version 7.0.0 or above Please upgrade to FortiPAM version 1.2.1 or above Please upgrade to FortiPAM version 1.1.3 or above Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.9 or above Please upgrade to FortiProxy version 7.0.16 or above