CVE-2024-23113
CVE Published | 2024-02-15 |
---|---|
Related CWE(s) | CWE-134: Use of Externally-Controlled Format String |
Related Vendor(s) | fortinet |
Related Product(s) | fortiproxy, fortios, fortipam, fortiswitchmanager |
Exploitation Reported (CISA KEV) | 2024-10-09 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph