CVE-2023-45583: Format String Bug in cli command
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.2, FortiSwitchManager 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.
Other sources
Multiple format string bug vulnerabilitues [CWE-134] in FortiOS, FortiProxy, FortiPAM & FortiSwitchManager command line interpreter and httpd may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted commands and http requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45583?
The severity of CVE-2023-45583 is classified as high, due to its potential to allow remote code execution via a format string vulnerability.
How do I fix CVE-2023-45583?
To fix CVE-2023-45583, upgrade Fortinet FortiOS to version 7.4.1 or higher, or FortiProxy to version 7.2.6 or higher.
Which versions are affected by CVE-2023-45583?
CVE-2023-45583 affects FortiOS versions including 7.2.0 through 7.2.5, as well as various versions of FortiProxy and FortiPAM.
Is there a workaround for CVE-2023-45583 if I cannot upgrade immediately?
Currently, there are no recommended workarounds for CVE-2023-45583, so timely upgrading is essential.
What products are impacted by CVE-2023-45583?
CVE-2023-45583 impacts multiple FortiNet products, including FortiOS, FortiProxy, and FortiPAM.