CVE-2023-44247: Double free with double usage of json_object_put
A double free vulnerability [CWE-415] in FortiOS may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPs requests.
Other sources
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44247?
CVE-2023-44247 is considered a critical vulnerability due to its potential to allow remote code execution by a privileged attacker.
How do I fix CVE-2023-44247?
To mitigate CVE-2023-44247, upgrade FortiOS to version 7.0.0 or later as this version addresses the vulnerability.
What types of attacks can exploit CVE-2023-44247?
CVE-2023-44247 can be exploited through crafted HTTP or HTTPS requests that leverage the double free vulnerability.
Which versions of FortiOS are affected by CVE-2023-44247?
CVE-2023-44247 affects FortiOS versions 6.2.x and 6.4.x up to specified versions before 7.0.0.
Can CVE-2023-44247 lead to unauthorized access?
Yes, CVE-2023-44247 can allow a privileged attacker to execute unauthorized code or commands on affected systems.