CVE-2023-23782

A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically crafted arguments to existing commands.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:46

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-22-111 - Vendor Advisory () https://fortiguard.com/psirt/FG-IR-22-111 - Vendor Advisory

Information

Published : 2023-02-16 19:15

Updated : 2024-11-21 07:46


NVD link : CVE-2023-23782

Mitre link : CVE-2023-23782

CVE.ORG link : CVE-2023-23782


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write