CyberSec.Space Logo
Back to CVE Browser

CVE-2023-27997

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2023-06-13
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

Affected Platforms (CPE)

📦
Fortinet

Fortiproxy

>= 1.1.0 and <= 1.1.6>= 1.2.0 and <= 1.2.13>= 2.0.0 and <= 2.0.12>= 7.0.0 and <= 7.0.9>= 7.2.0 and <= 7.2.3
💻
Fortinet

Fortios

>= 6.0.0 and <= 6.0.16>= 6.2.0 and <= 6.2.13>= 6.4.0 and <= 6.4.12>= 7.0.0 and <= 7.0.11>= 7.2.0 and <= 7.2.4>= 6.0.12 and <= 6.0.16>= 6.2.9 and <= 6.2.13= 6.0.10= 6.2.4= 6.2.6= 6.2.7= 6.4.2= 6.4.6= 6.4.8= 6.4.10= 6.4.12= 7.0.5= 7.0.10

References & Advisories

Related Vulnerabilities