CVE-2023-46720: Stack buffer overflow on bluetooth write feature
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.
Other sources
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in FortiOS may allow an authenticated attacker to achieve arbitrary code execution via specially crafted CLI commands.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46720?
CVE-2023-46720 is considered a critical vulnerability due to its potential for unauthorized code execution.
How do I fix CVE-2023-46720?
To fix CVE-2023-46720, update FortiOS to version 7.4.4, 7.2.8, or 7.0.16, depending on your current version.
Which versions of FortiOS are affected by CVE-2023-46720?
FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.7, 7.0.0 through 7.0.12, and several 6.x versions are affected.
What type of vulnerability is CVE-2023-46720?
CVE-2023-46720 is a stack-based buffer overflow vulnerability.
Can CVE-2023-46720 lead to remote code execution?
Yes, CVE-2023-46720 allows an attacker to execute unauthorized code or commands remotely.