CVE-2023-25610
55Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 9.3epss 18%
da publicação à arma0 dias
Publicada no NVD24 de mar.
1ª PoC17 de jun.
probabilidade de exploração
18%top 3% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
Produtos afetados
Fortinet · FortiAnalyzerFortinet · FortiManagerFortinet · FortiOSFortinet · FortiOS-6K7KFortinet · FortiProxyFortinet · FortiSwitchManagerFortinet · FortiWebPoCs públicas encontradas — 1
githubgithub.com/qi4L/CVE-2023-25610★ 23⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://fortiguard.com/psirt/FG-IR-23-001