FG-IR-23-304: Format string vulnerability in administrative interface
A use of externally-controlled format string vulnerability [CWE-134] in FortiManager, FortiAnalyzer, FortiAnalyzer-BigData & FortiPortal may allow a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-304?
The severity of FG-IR-23-304 is critical due to the potential for privileged attackers to execute unauthorized code or commands.
How do I fix FG-IR-23-304?
To fix FG-IR-23-304, it is recommended to update FortiManager, FortiAnalyzer, FortiAnalyzer-BigData, and FortiPortal to the latest patched versions.
What products are affected by FG-IR-23-304?
FG-IR-23-304 affects FortiManager, FortiAnalyzer, FortiAnalyzer-BigData, and FortiPortal.
What is the nature of the vulnerability in FG-IR-23-304?
FG-IR-23-304 is a use of externally-controlled format string vulnerability that can lead to unauthorized code execution.
Who can exploit FG-IR-23-304?
FG-IR-23-304 can be exploited by privileged attackers through specially crafted command arguments.