CVE-2023-40721
6.7MEDIUMA use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
Published: 2/11/2025Updated: 1/14/2026
Description
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
AI AnalysisPowered by AI
Affected Products
fortinetfortios
fortinetfortios
fortinetfortios
7.4.0
fortinetfortiswitchmanager
fortinetfortiswitchmanager
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy
7.4.0
fortinetfortipam
References
- https://fortiguard.com/psirt/FG-IR-23-261Vendor Advisory