Lucene search

K
nvd[email protected]NVD:CVE-2023-22639
HistoryJun 13, 2023 - 9:15 a.m.

CVE-2023-22639

2023-06-1309:15:16
CWE-787
web.nvd.nist.gov
2
cve-2023-22639
fortinet fortios
out-of-bounds write
privilege escalation
fortiproxy

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

9.0%

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows attacker to escalation of privilege via specifically crafted commands.

Affected configurations

Nvd
Node
fortinetfortiproxyRange1.0.01.0.7
OR
fortinetfortiproxyRange1.1.01.1.6
OR
fortinetfortiproxyRange1.2.01.2.13
OR
fortinetfortiproxyRange2.0.02.0.12
OR
fortinetfortiproxyRange7.0.07.0.8
OR
fortinetfortiproxyMatch7.2.0
OR
fortinetfortiproxyMatch7.2.1
OR
fortinetfortiproxyMatch7.2.2
OR
fortinetfortiosRange6.0.06.0.17
OR
fortinetfortiosRange6.2.06.2.15
OR
fortinetfortiosRange6.4.06.4.12
OR
fortinetfortiosRange7.0.07.0.9
OR
fortinetfortiosRange7.2.07.2.3
VendorProductVersionCPE
fortinetfortiproxy*cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
fortinetfortiproxy7.2.0cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
fortinetfortiproxy7.2.1cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
fortinetfortiproxy7.2.2cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:*
fortinetfortios*cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-22639