Vulnerability Description
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows attacker to escalation of privilege via specifically crafted commands.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiproxy | >= 1.0.0, <= 1.0.7 |
| Fortinet | Fortios | >= 6.0.0, <= 6.0.17 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-22-494Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-22-494Vendor Advisory
FAQ
What is CVE-2023-22639?
CVE-2023-22639 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, F...
How severe is CVE-2023-22639?
CVE-2023-22639 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22639?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiproxy, Fortinet Fortios.