CVE Vulnerabilities

CVE-2023-41678

Double Free

Published: Dec 13, 2023 | Modified: Dec 15, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 7.0.0 (including) 7.0.0 (including)
Fortios Fortinet 7.0.1 (including) 7.0.1 (including)
Fortios Fortinet 7.0.2 (including) 7.0.2 (including)
Fortios Fortinet 7.0.3 (including) 7.0.3 (including)
Fortios Fortinet 7.0.4 (including) 7.0.4 (including)
Fortios Fortinet 7.0.5 (including) 7.0.5 (including)
Fortipam Fortinet 1.0.0 (including) 1.0.0 (including)
Fortipam Fortinet 1.0.1 (including) 1.0.1 (including)
Fortipam Fortinet 1.0.2 (including) 1.0.2 (including)
Fortipam Fortinet 1.0.3 (including) 1.0.3 (including)
Fortipam Fortinet 1.1.0 (including) 1.1.0 (including)
Fortipam Fortinet 1.1.1 (including) 1.1.1 (including)

Potential Mitigations

References