CVE-2023-22639: Out-of-bound write in CLI
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows attacker to escalation of privilege via specifically crafted commands.
Other sources
An out-of-bounds write vulnerability [CWE-787] in Command Line Interface of FortiOS and FortiProxy may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted commands.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-22639?
CVE-2023-22639 is a vulnerability in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions.
What is the severity of CVE-2023-22639?
The severity of CVE-2023-22639 is high (7.8).
How does CVE-2023-22639 affect Fortinet FortiOS?
CVE-2023-22639 affects Fortinet FortiOS versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 6.4.0 through 6.4.12, 6.2, and 6.0.
How does CVE-2023-22639 affect FortiProxy?
CVE-2023-22639 affects FortiProxy versions 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8.
Is there a fix for CVE-2023-22639?
Yes, updating to a version of Fortinet FortiOS or FortiProxy that is not affected by CVE-2023-22639 will fix the vulnerability.