Fiche vulnérabilité
CVE-2023-23782 : faille élevée Fortinet FortiWeb (CVSS 7.1)
Description
A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically crafted arguments to existing commands.
En bref
- Sévérité
- Élevée (CVSS 7.1)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:R
- Exploitation active
- Non signalée par la CISA
- Publication
- 16 févr. 2023
- Dernière mise à jour
- 23 oct. 2024
Produits concernés
- Fortinet FortiWeb
Correctif et mesures
Upgrade to FortiWeb 7.0.2 or above, upgrade to FortiWeb 6.3.20 or above.