Critical severity9.8NVD Advisory· Published Mar 12, 2024· Updated Jul 8, 2026
CVE-2023-42789
CVE-2023-42789
Description
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.0.13
- cpe:2.3:a:fortinet:fortiproxy:7.4.0:*:*:*:*:*:*:*
- (no CPE)range: 7.4.0, 7.2.0-7.2.6, 7.0.0-7.0.12, 2.0.0-2.0.13
- (no CPE)range: 7.4.0
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.2.0,<=6.2.15
- cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:7.4.1:*:*:*:*:*:*:*
- (no CPE)range: 7.4.0-7.4.1, 7.2.0-7.2.5, 7.0.0-7.0.12, 6.4.0-6.4.14, 6.2.0-6.2.15
- (no CPE)range: 7.4.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-328nvdVendor Advisory
News mentions
0No linked articles in our index yet.