CVE-2023-23782: Buffer Overflow
A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically crafted arguments to existing commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this heap-based buffer overflow?
The vulnerability ID for this heap-based buffer overflow is CVE-2023-23782.
Which software versions are affected by this vulnerability?
The affected software versions are Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, and FortiWeb 6.2 all versions.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by providing specifically crafted arguments to existing commands.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is 7.8 (high).
How can I fix this vulnerability?
To fix this vulnerability, update to a version outside the affected range specified.