CVE-2023-22640: High severity fortinet fortiproxy ssl vpn webmode vulnerability
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-22640?
CVE-2023-22640 is a vulnerability in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, and FortiOS all versions 6.0, as well as FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, and FortiProxy version 1.0.0 through 2.0.0.
How severe is CVE-2023-22640?
CVE-2023-22640 has a severity rating of 8.8 (High).
What is the affected software for CVE-2023-22640?
The affected software for CVE-2023-22640 includes Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, and FortiProxy version 1.0.0 through 2.0.0.
Is there a fix available for CVE-2023-22640?
Yes, there is a fix available for CVE-2023-22640. It is recommended to update to the latest version of Fortinet FortiOS or FortiProxy that includes a patch for the vulnerability.
Where can I find more information about CVE-2023-22640?
You can find more information about CVE-2023-22640 on the FortiGuard website at https://fortiguard.com/psirt/FG-IR-22-475.