Loading HuntDB...

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Added June 13, 2023 Due July 4, 2023 CVE-2023-27997
Overdue Fortinet / FortiOS and FortiProxy SSL-VPN Known Ransomware Use CWE-122

Description

Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
4 months, 3 weeks ago