Medium severity6.7NVD Advisory· Published Feb 11, 2025· Updated Jun 17, 2026
CVE-2023-40721
CVE-2023-40721
Description
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
Affected products
9cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.2.0,<7.0.15
- cpe:2.3:a:fortinet:fortiproxy:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*range: >=7.0.0,<7.0.3
- cpe:2.3:a:fortinet:fortiswitchmanager:7.2.2:*:*:*:*:*:*:*range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-261nvdVendor Advisory
News mentions
0No linked articles in our index yet.