CVE Vulnerabilities

CVE-2023-41678

Double Free

Published: Dec 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
FortiosFortinet7.0.0 (including)7.0.0 (including)
FortiosFortinet7.0.1 (including)7.0.1 (including)
FortiosFortinet7.0.2 (including)7.0.2 (including)
FortiosFortinet7.0.3 (including)7.0.3 (including)
FortiosFortinet7.0.4 (including)7.0.4 (including)
FortiosFortinet7.0.5 (including)7.0.5 (including)
FortipamFortinet1.0.0 (including)1.0.0 (including)
FortipamFortinet1.0.1 (including)1.0.1 (including)
FortipamFortinet1.0.2 (including)1.0.2 (including)
FortipamFortinet1.0.3 (including)1.0.3 (including)
FortipamFortinet1.1.0 (including)1.1.0 (including)
FortipamFortinet1.1.1 (including)1.1.1 (including)

Potential Mitigations

References