CVE-2022-43953

MEDIUM

Fortinet FortiOS <7.2.4 - Code Injection

Title source: llm
STIX 2.1

Description

A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via specially crafted commands.

Scores

CVSS v3 6.7
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-134
Status published
Products (4)
fortinet/fortios 6.2.0 - 6.2.15
fortinet/fortiproxy 7.2.0
fortinet/fortiproxy 7.2.1
fortinet/fortiproxy 7.0.0 - 7.0.7
Published Jun 13, 2023
Tracked Since Feb 18, 2026