FG-IR-23-097: Heap buffer overflow in sslvpn pre-authentication
Published Jun 12, 2023
·Updated
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiProxy SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
Workaround:
Disable SSL-VPN.
Affected Software
2 affected components
Fortinet FortiOS
Fortinet FortiProxy
Event History
Jun 12, 2023
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-23-097?
The severity of FG-IR-23-097 is high due to the potential for remote code execution.
2
How do I fix FG-IR-23-097?
To mitigate FG-IR-23-097, disable the SSL-VPN feature on affected FortiOS and FortiProxy devices.
3
What systems are affected by FG-IR-23-097?
FG-IR-23-097 affects Fortinet FortiOS and FortiProxy SSL-VPN systems.
4
Can FG-IR-23-097 lead to data breaches?
Yes, FG-IR-23-097 can potentially lead to data breaches if exploited by an attacker.
5
Is there a patch available for FG-IR-23-097?
As of now, a specific patch has not been released for FG-IR-23-097, so disabling SSL-VPN is the recommended workaround.