CVE-2023-27997: Heap buffer overflow in sslvpn pre-authentication
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiProxy SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
Workaround:
Disable SSL-VPN.
Other sources
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 6.0.17 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 6.2.14 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 6.4.13 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.0.12 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.5 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.0 - Upgrade
Upgrade
FortiOS-6K7Kto a version that resolves this vulnerability.Fixed in 6.0.17 - Upgrade
Upgrade
FortiOS-6K7Kto a version that resolves this vulnerability.Fixed in 6.2.15 - Upgrade
Upgrade
FortiOS-6K7Kto a version that resolves this vulnerability.Fixed in 6.4.13 - Upgrade
Upgrade
FortiOS-6K7Kto a version that resolves this vulnerability.Fixed in 7.0.12 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.10 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.4 - Configuration
Disable SSL-VPN on affected FortiOS devices.
FortiOS SSL-VPN SSL-VPN = disabled - Configuration
Disable SSL-VPN webmode on affected FortiProxy devices.
FortiProxy SSL-VPN (webmode) SSL-VPN = disabled
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.