A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
The vulnerability lies in improper buffer boundary handling in the administrative layer, where a crafted network request causes data to be written below the start of the reserved memory area (buffer underflow, CWE-124). The attacker sends specially constructed HTTP/HTTPS requests to the device's management interface without needing any credentials. Improper memory overwrite can lead to hijacking control of the process execution flow and running arbitrary code with the process's privileges.
An attacker can remotely execute arbitrary code or system commands on a vulnerable device without authentication, which in practice means complete takeover of the network device (firewall, proxy, switch manager) and potential lateral movement within the organization's network.
Patches available from the vendor must be applied immediately according to references (https://fortiguard.com/psirt/FG-IR-23-001). As a mitigation measure, if immediate update is not possible, access to the administrative interface should be restricted to trusted hosts and management networks only, and access from the Internet to administrative ports on all vulnerable devices should be blocked.
FortiOS 7.2.0–7.2.3, 7.0.0–7.0.6, 6.4.0–6.4.11, 6.2.12 and earlier; FortiProxy 7.2.0–7.2.2, 7.0.0–7.0.8, 2.0.12 and earlier; FortiOS-6K7K 7.0.5, 6.4.0–6.4.10, 6.2.0–6.2.10 and earlier; products from FortiSwitch, FortiSwitchManager and FortiManager lines (versions indicated in vendor references)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFortinet Fortianalyzer
APPFortinet7.2.07.0.0 – 7.0.5 (excl.)6.4.0 – 6.4.12 (excl.)6.2.0 – 6.2.11 (excl.)6.0.0 – 6.0.12 (excl.)Fortinet Fortimanager
APPFortinet7.2.06.2.0 – 6.2.11 (excl.)7.0.0 – 7.0.5 (excl.)6.4.0 – 6.4.12 (excl.)6.0.0 – 6.0.12 (excl.)Fortinet FortiOS
OSFortinet6.4.0 – 6.4.12 (excl.)7.2.0 – 7.2.4 (excl.)7.0.0 – 7.0.10 (excl.)5.0.0 – 6.2.13 (excl.)Fortinet FortiOS 6k7k
APPFortinet7.0.56.4.2 – 6.4.12 (excl.)6.0.4 – 6.2.13 (excl.)Fortinet Fortiproxy
APPFortinet7.2.0 – 7.2.3 (excl.)1.1.0 – 7.0.9 (excl.)Fortinet Fortiswitch
OSFortinet7.0.0 – 7.0.7 (excl.)7.2.0 – 7.2.4 (excl.)Fortinet Fortiswitchmanager
APPFortinet7.2.0 – 7.2.2 (excl.)7.0.0 – 7.0.2 (excl.)Fortinet Fortiweb
APPFortinet6.2.0 – 6.2.8 (excl.)7.2.0 – 7.2.2 (excl.)7.0.0 – 7.0.7 (excl.)6.4.0 – 6.4.3 (excl.)6.3.0 – 6.3.23 (excl.)6.1.0 – 6.1.4 (excl.)
Related vulnerabilities
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML
Path Traversal w Fortinet FortiWeb umożliwiający zdalne wykonanie poleceń
Krytyczna podatność SQL Injection w Fortinet FortiWeb — obejście uwierzytelnienia
Authentication Bypass w FortiOS i FortiProxy — przejęcie uprawnień super-admin