Record summary

CVE-2023-25610 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC.

Description

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2025 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List7.2.0affected
7.0.0 to ≤ 7.0.4affected
6.4.0 to ≤ 6.4.11affected
6.2.0 to ≤ 6.2.10affected
6.0.0 to ≤ 6.0.11affected

Default status: unaffected

CVE List7.2.0affected
7.0.0 to ≤ 7.0.4affected
6.4.0 to ≤ 6.4.11affected
6.2.0 to ≤ 6.2.10affected
6.0.0 to ≤ 6.0.11affected

Default status: unaffected

CVE List7.2.0 to ≤ 7.2.3affected
7.0.0 to ≤ 7.0.9affected
6.4.0 to ≤ 6.4.11affected
6.2.0 to ≤ 6.2.12affected
6.0.0 to ≤ 6.0.18affected
5.6.0 to ≤ 5.6.14affected
5.4.0 to ≤ 5.4.13affected
5.2.0 to ≤ 5.2.15affected
5.0.0 to ≤ 5.0.14affected

Default status: unaffected

CVE List, NVD7.0.5affected
6.4.10affected
6.4.8affected
6.4.6affected
6.4.2affected
6.2.9 to ≤ 6.2.12affected
6.2.6 to ≤ 6.2.7affected
6.2.4affected
6.0.12 to ≤ 6.0.18affected
6.0.10affected

Default status: unaffected

CVE List, NVD7.2.0 to ≤ 7.2.2affected
7.0.0 to ≤ 7.0.8affected
2.0.0 to ≤ 2.0.14affected
1.2.0 to ≤ 1.2.13affected
1.1.0 to ≤ 1.1.6affected

Default status: unaffected

CVE List, NVD7.2.0 to ≤ 7.2.1affected
7.0.0 to ≤ 7.0.1affected

Default status: unaffected

CVE List, NVD7.2.0 to ≤ 7.2.1affected
7.0.0 to ≤ 7.0.6affected
6.4.0 to ≤ 6.4.2affected
6.3.0 to ≤ 6.3.22affected
6.2.0 to ≤ 6.2.7affected
6.1.0 to ≤ 6.1.3affected

Proofs of concept

1

Repository PoCs

GitHubqi4L/CVE-2023-25610Repository PoCby qi4LStars: 23Not analyzed9 files

4.6 KiB

GitHub

PoC details

References

2