VYPR
Medium severity6.7NVD Advisory· Published Feb 11, 2025· Updated Jun 17, 2026

CVE-2023-40721

CVE-2023-40721

Description

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

Affected products

9
  • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.2.0,<7.0.15
    • cpe:2.3:a:fortinet:fortiproxy:7.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*range: >=7.0.0,<7.0.3
    • cpe:2.3:a:fortinet:fortiswitchmanager:7.2.2:*:*:*:*:*:*:*range: 7.2.0
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.2.0,<7.0.14
    • cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:*
  • Fortinet/Fortipam2 versions
    cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*range: >=1.0.0,<1.2.0
    • cpe:2.3:o:fortinet:fortipam:1.1.2:*:*:*:*:*:*:*range: 1.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.