FG-IR-23-137: Format String Bug in cli command
Multiple format string bug vulnerabilitues [CWE-134] in FortiOS, FortiProxy, FortiPAM & FortiSwitchManager command line interpreter and httpd may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted commands and http requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-137?
FG-IR-23-137 has a high severity rating due to the potential for arbitrary code execution by an authenticated attacker.
How do I fix FG-IR-23-137?
To fix FG-IR-23-137, upgrade FortiOS, FortiProxy, FortiPAM, or FortiSwitchManager to the recommended versions or later.
Which products are affected by FG-IR-23-137?
FG-IR-23-137 affects FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager with various version ranges.
Can FG-IR-23-137 be exploited remotely?
FG-IR-23-137 requires authentication, hence exploitation must come from an authenticated attacker.
What are the potential impacts of FG-IR-23-137?
The potential impacts of FG-IR-23-137 include arbitrary code execution, which can lead to system compromise.