Fiche vulnérabilité
CVE-2023-46714 : faille moyenne Fortinet FortiOS (CVSS 6.8)
Description
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.
En bref
- Sévérité
- Moyenne (CVSS 6.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
- Exploitation active
- Non signalée par la CISA
- Publication
- 14 mai 2024
- Dernière mise à jour
- 2 août 2024
Produits concernés
- Fortinet FortiOS
Correctif et mesures
Please upgrade to FortiOS version 7.4.2 or above Please upgrade to FortiOS version 7.2.8 or above Please upgrade to FortiAuthenticator version 6.6.1 or above Please upgrade to FortiAuthenticator version 6.5.5 or above