Vulnerability Description
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiproxy | >= 7.0.0, <= 7.0.9 |
| Fortinet | Fortios | >= 7.0.0, <= 7.0.10 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-23-183Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-23-183Vendor Advisory
FAQ
What is CVE-2023-33308?
CVE-2023-33308 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remo...
How severe is CVE-2023-33308?
CVE-2023-33308 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-33308?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiproxy, Fortinet Fortios.