A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiproxy | — | Upgrade FortiProxy to 7.0.16Upgrade to the latest version of FortiProxyUpgrade FortiProxy to 7.4.3Upgrade FortiProxy to 7.2.9 | Sep 30, 2026 | Feb 8, 2024 |
| Fortinet Fortiswitchmanager | — | Upgrade FortiSwitchManager to 7.2.4Upgrade to the latest version of FortiSwitchManagerUpgrade FortiSwitchManager to 7.0.4 | Sep 30, 2026 | Feb 8, 2024 |
| Fortios | — | Upgrade FortiOS to 7.0.14Upgrade FortiOS to 7.4.3Upgrade FortiOS to 7.2.7 | Feb 12, 2024 | Feb 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub