CVE-2023-45584: Double free in automation-stitch
A double free vulnerability [CWE-415] in FortiOS, FortiProxy & FortiPAM administrative interfaces may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
Other sources
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45584?
CVE-2023-45584 is considered a high severity vulnerability due to its potential exploitation by privileged attackers.
How do I fix CVE-2023-45584?
To fix CVE-2023-45584, upgrade FortiOS to versions 7.4.1 or higher, FortiProxy to versions 7.2.8 or higher, or FortiPAM to versions 1.1.3 or higher.
What products are affected by CVE-2023-45584?
CVE-2023-45584 affects Fortinet FortiOS versions 7.4.0, 7.2.0 through 7.2.5, FortiProxy versions 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7, as well as FortiPAM versions 1.1.0 through 1.1.2.
What type of vulnerability is CVE-2023-45584?
CVE-2023-45584 is a double free vulnerability, categorized under CWE-415, which can lead to memory corruption and potential system exploitation.
Who can be impacted by CVE-2023-45584?
CVE-2023-45584 can impact organizations using vulnerable versions of Fortinet products, potentially allowing privileged attackers to execute arbitrary code.