CVE Vulnerabilities

CVE-2023-25610

Buffer Underwrite ('Buffer Underflow')

Published: Mar 24, 2025 | Modified: Jul 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A buffer underwrite (buffer underflow) vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Weakness

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software

NameVendorStart VersionEnd Version
FortiwebFortinet6.1.0 (including)6.1.4 (excluding)
FortiwebFortinet6.2.0 (including)6.2.8 (excluding)
FortiwebFortinet6.3.0 (including)6.3.23 (excluding)
FortiwebFortinet6.4.0 (including)6.4.3 (excluding)
FortiwebFortinet7.0.0 (including)7.0.7 (excluding)
FortiwebFortinet7.2.0 (including)7.2.2 (excluding)

Potential Mitigations

References