CVE-2023-27997
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
CVSS
9.8
Crítico
EPSS
85.7%
p100
KEV
SÍ
13 jun 2023
Exploit Today
80
0-100
Publicado: 13 jun 2023 · Última mod.: 31 jul 2026 · CWE-122 · CWE-787
Producto
Fortinet / FortiOS and FortiProxy SSL-VPN
Vulnerabilidad
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
Añadido a KEV
13 jun 2023
Remediar antes de
4 jul 2023
Uso conocido en ransomware
Sí
Descripción resumida
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.
Acción requerida
Apply updates per vendor instructions.
Notas
https://www.fortiguard.com/psirt/FG-IR-23-097; https://nvd.nist.gov/vuln/detail/CVE-2023-27997
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.