FG-IR-23-261: FortiOS / FortiProxy / FortiPAM / FortiSwitchManager - Format string vulnerability in CLI commands
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS, FortiProxy, FortiPAM & FortiSwitchManager CLI may allow a privileged attacker to execute arbitrary code or commands via specially crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-261?
The severity of FG-IR-23-261 is critical due to potential arbitrary code execution by an attacker.
How do I fix FG-IR-23-261?
To fix FG-IR-23-261, update FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager to the latest available versions that include the security patches.
Who is affected by FG-IR-23-261?
FG-IR-23-261 affects users of FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager.
What type of vulnerability is FG-IR-23-261?
FG-IR-23-261 is classified as a use of externally-controlled format string vulnerability.
What can an attacker do with FG-IR-23-261?
An attacker exploiting FG-IR-23-261 can execute arbitrary code or commands through specially crafted requests.