CVE-2023-48784: FortiOS - Format String in CLI command
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests.
Other sources
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS command line interface may allow a local privileged attacker with CLI access to execute arbitrary code or commands via specially crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-48784?
CVE-2023-48784 is classified as a critical vulnerability due to its potential to allow local privileged attackers to execute arbitrary code.
How do I fix CVE-2023-48784?
To remediate CVE-2023-48784, upgrade to FortiOS version 7.4.2, 7.2.8, or 7.0.16 or later.
Which versions of FortiOS are affected by CVE-2023-48784?
CVE-2023-48784 affects FortiOS versions 7.4.1 and below, 7.2.7 and below, 7.0 all versions, and 6.4 all versions.
Who can exploit CVE-2023-48784?
CVE-2023-48784 can be exploited by local privileged attackers who have access to the CLI with a super-admin profile.
Is CVE-2023-48784 a remote vulnerability?
No, CVE-2023-48784 is a local vulnerability that requires physical or privileged CLI access to exploit.