use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized code or commands via specially crafted commands
| Link | Resource |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-137 | Vendor Advisory |
| https://fortiguard.com/psirt/FG-IR-23-137 | Vendor Advisory |
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
21 Nov 2024, 08:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.com/psirt/FG-IR-23-137 - Vendor Advisory |
23 May 2024, 17:46
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet fortios
Fortinet Fortinet fortiproxy Fortinet fortipam |
|
| References | () https://fortiguard.com/psirt/FG-IR-23-137 - Vendor Advisory | |
| Summary |
|
|
| CPE | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* |
14 May 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-05-14 17:15
Updated : 2024-11-21 08:10
NVD link : CVE-2023-36640
Mitre link : CVE-2023-36640
CVE.ORG link : CVE-2023-36640
JSON object : View
Use of Externally-Controlled Format String