CVE ID
CVE-2023-27997
Vulnerability Name
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
- Project: Fortinet
- Product: FortiOS and FortiProxy SSL-VPN
Date
- Date Added: 2023-06-13
- Due Date: 2023-07-04
Description
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply updates per vendor instructions.
Additional Notes
https://www.fortiguard.com/psirt/FG-IR-23-097; https://nvd.nist.gov/vuln/detail/CVE-2023-27997
Related Security News
- Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
- Critical Fortinet flaws now exploited in Qilin ransomware attacks
- Fortinet Warns Attackers Retain FortiGate Access Post-Patching via SSL-VPN Symlink Exploit
- Hackers exploit old FortiGate vulnerabilities, use symlink trick to retain limited access to patched devices
- Fortinet: Hackers retain access to patched FortiGate VPNs using symlinks
- Chinese APT Group Is Ransacking Japan's Secrets
- MirrorFace hackers targeting Japanese govt, politicians since 2019
- CISA Urges Agencies to Patch Critical "Array Networks" Flaw Amid Active Attacks
- Fortinet warns of new critical FortiManager flaw used in zero-day attacks
- Google: 70% of exploited flaws disclosed in 2023 were zero-days
Top comments (0)