CVE-2023-25610
CRITICALDescription
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Is your site exposed to CVE-2023-25610?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortiswitchmanager |
| fortinet | fortiswitchmanager |
| fortinet | fortiswitch |
| fortinet | fortiswitch |
| fortinet | fortiproxy |
| fortinet | fortiproxy |
| fortinet | fortios-6k7k |
| fortinet | fortios-6k7k |
| fortinet | fortios-6k7k |
| fortinet | fortios |
| fortinet | fortios |
| fortinet | fortios |
| fortinet | fortios |
| fortinet | fortimanager |
| fortinet | fortimanager |
| fortinet | fortimanager |
| fortinet | fortimanager |
| fortinet | fortimanager |
| fortinet | fortianalyzer |
| fortinet | fortianalyzer |
| fortinet | fortianalyzer |
| fortinet | fortianalyzer |
| fortinet | fortianalyzer |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-25610? +
How severe is CVE-2023-25610? +
What products are affected by CVE-2023-25610? +
How do I check if I'm vulnerable to CVE-2023-25610? +
Related Vulnerabilities
In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out …
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked …
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: …
Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network …
Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network …