CVE-2023-41678: Double free in cache management
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
Other sources
A double free vulnerability [CWE-415] in FortiOS and FortiPAM HTTPSd daemon may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted commands.
— FortiGuard
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-41678?
CVE-2023-41678 is rated as critical due to its potential for unauthorized code execution.
How do I fix CVE-2023-41678?
To mitigate CVE-2023-41678, upgrade to a patched version of FortiOS or FortiPAM as recommended by Fortinet.
What systems are affected by CVE-2023-41678?
CVE-2023-41678 affects Fortinet FortiOS versions 7.0.0 through 7.0.5 and FortiPAM versions 1.0.0 through 1.1.1.
What type of vulnerability is CVE-2023-41678?
CVE-2023-41678 is a double free vulnerability, which is classified under CWE-415.
Can CVE-2023-41678 be exploited remotely?
Yes, CVE-2023-41678 can be exploited remotely through specially crafted requests.