CVE-2024-23113: Fortinet Multiple Products Format String Vulnerability
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
Other sources
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. A third-party report is indicating this may be exploited in the wild.
— FortiGuard
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.0.14 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.7 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.3 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.1.3 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.2.1 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.16 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.9 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.3 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.0.4 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.2.4 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 6.4.9 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 7.0.2 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.4.3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-23113?
CVE-2024-23113 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-23113?
To mitigate CVE-2024-23113, upgrade FortiOS, FortiProxy, or FortiPAM to the latest recommended versions: 7.4.3 or higher, 7.2.9 or higher, or 1.2.0 respectively.
Which Fortinet products are affected by CVE-2024-23113?
CVE-2024-23113 affects multiple Fortinet products, including FortiOS, FortiProxy, and FortiPAM across various versions.
What type of vulnerability is CVE-2024-23113?
CVE-2024-23113 is a use of externally-controlled format string vulnerability.
Are there known exploits for CVE-2024-23113?
Yes, CVE-2024-23113 has been reported to be actively exploited in the wild.