CVE-2023-25602: Buffer Overflow
A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb versions 6.2.6 and earlier, FortiWeb versions 6.1.2 and earlier, FortiWeb versions 6.0.7 and earlier, FortiWeb versions 5.9.1 and earlier, FortiWeb 5.8 all versions, FortiWeb 5.7 all versions, FortiWeb 5.6 all versions allows attacker to execute unauthorized code or commands via specially crafted command arguments.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-25602?
CVE-2023-25602 is a stack-based buffer overflow vulnerability in Fortinet FortiWeb.
What versions of Fortinet FortiWeb are affected by CVE-2023-25602?
CVE-2023-25602 affects FortiWeb versions 6.4.0 to 6.4.2, 6.3.0 to 6.3.18, 6.2.0 to 6.2.7, 6.1.0 to 6.1.3, 6.0.0 to 6.0.8, and 5.6.0 to 5.9.2.
What is the severity of CVE-2023-25602?
The severity of CVE-2023-25602 is rated as high, with a CVSS score of 7.8.
How does CVE-2023-25602 impact Fortinet FortiWeb?
CVE-2023-25602 can lead to a stack-based buffer overflow, potentially allowing an attacker to execute arbitrary code or cause a denial-of-service.
Is there a fix available for CVE-2023-25602?
Yes, Fortinet has released patches to address the CVE-2023-25602 vulnerability. It is recommended to update to the latest patched version of FortiWeb.