Medium severity6.7NVD Advisory· Published Mar 12, 2024· Updated Jun 17, 2026
CVE-2023-41842
CVE-2023-41842
Description
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
Affected products
10cpe:2.3:a:fortinet:fortianalyzer-bigdata:7.2.5:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortianalyzer-bigdata:7.2.5:*:*:*:*:*:*:*range: 7.2.0
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.2.0,<7.0.10
- cpe:2.3:o:fortinet:fortianalyzer:7.4.1:*:*:*:*:*:*:*range: 7.4.0
cpe:2.3:a:fortinet:fortianalyzer_big_data:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortianalyzer_big_data:*:*:*:*:*:*:*:*range: >=6.4.5,<=6.4.7
- cpe:2.3:a:fortinet:fortianalyzer_big_data:6.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >=6.2.0,<7.0.10
- cpe:2.3:o:fortinet:fortimanager:7.4.1:*:*:*:*:*:*:*range: 7.4.0
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*range: >=5.3.0,<6.0.15
- cpe:2.3:a:fortinet:fortiportal:6.0.14:*:*:*:*:*:*:*range: 6.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-304nvdVendor Advisory
News mentions
0No linked articles in our index yet.