FG-IR-23-413: FortiOS - Format String in CLI command
Published Apr 9, 2024
·Updated
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS command line interface may allow a local privileged attacker with CLI access to execute arbitrary code or commands via specially crafted requests.
Affected Software
4 affected componentsFixes available
Fortinet FortiOS>=7.4.0<=7.4.1
Fortinet FortiOS>=7.2.0<=7.2.7
Fortinet FortiOS>=7.0.0<=7.0.15
Fortinet FortiOS>=6.4
Event History
Apr 9, 2024
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Dec 2, 2024
Advisory Published
via FortiGuard·01:00 PM
Frequently Asked Questions
1
What is the severity of FG-IR-23-413?
The severity of FG-IR-23-413 is considered critical due to its potential for arbitrary code execution.
2
How do I fix FG-IR-23-413?
To fix FG-IR-23-413, upgrade FortiOS to version 7.4.2 or higher, 7.2.8 or higher, or 7.0.16 or higher, as applicable.
3
Who is affected by FG-IR-23-413?
FG-IR-23-413 affects all versions of FortiOS prior to 7.4.2, 7.2.8, and 7.0.16.
4
What type of vulnerability is FG-IR-23-413?
FG-IR-23-413 is a use of externally-controlled format string vulnerability classified under CWE-134.
5
Can FG-IR-23-413 be exploited remotely?
FG-IR-23-413 requires local CLI access, making it a local attack vector rather than a remote exploit.