CVE-2023-25610
Record summary
CVE-2023-25610 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC.
Description
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2025 · Source: CVE List
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
FortiAnalyzerBrowse Fortinet / FortiAnalyzerDefault status: unaffected | CVE List | 7.2.0 | affected |
| 7.0.0 to ≤ 7.0.4 | affected | ||
| 6.4.0 to ≤ 6.4.11 | affected | ||
| 6.2.0 to ≤ 6.2.10 | affected | ||
| 6.0.0 to ≤ 6.0.11 | affected | ||
FortiManagerBrowse Fortinet / FortiManagerDefault status: unaffected | CVE List | 7.2.0 | affected |
| 7.0.0 to ≤ 7.0.4 | affected | ||
| 6.4.0 to ≤ 6.4.11 | affected | ||
| 6.2.0 to ≤ 6.2.10 | affected | ||
| 6.0.0 to ≤ 6.0.11 | affected | ||
FortiOSBrowse Fortinet / FortiOSDefault status: unaffected | CVE List | 7.2.0 to ≤ 7.2.3 | affected |
| 7.0.0 to ≤ 7.0.9 | affected | ||
| 6.4.0 to ≤ 6.4.11 | affected | ||
| 6.2.0 to ≤ 6.2.12 | affected | ||
| 6.0.0 to ≤ 6.0.18 | affected | ||
| 5.6.0 to ≤ 5.6.14 | affected | ||
| 5.4.0 to ≤ 5.4.13 | affected | ||
| 5.2.0 to ≤ 5.2.15 | affected | ||
| 5.0.0 to ≤ 5.0.14 | affected | ||
FortiOS-6K7KBrowse Fortinet / FortiOS-6K7KDefault status: unaffected | CVE List, NVD | 7.0.5 | affected |
| 6.4.10 | affected | ||
| 6.4.8 | affected | ||
| 6.4.6 | affected | ||
| 6.4.2 | affected | ||
| 6.2.9 to ≤ 6.2.12 | affected | ||
| 6.2.6 to ≤ 6.2.7 | affected | ||
| 6.2.4 | affected | ||
| 6.0.12 to ≤ 6.0.18 | affected | ||
| 6.0.10 | affected | ||
FortiProxyBrowse Fortinet / FortiProxyDefault status: unaffected | CVE List, NVD | 7.2.0 to ≤ 7.2.2 | affected |
| 7.0.0 to ≤ 7.0.8 | affected | ||
| 2.0.0 to ≤ 2.0.14 | affected | ||
| 1.2.0 to ≤ 1.2.13 | affected | ||
| 1.1.0 to ≤ 1.1.6 | affected | ||
FortiSwitchManagerBrowse Fortinet / FortiSwitchManagerDefault status: unaffected | CVE List, NVD | 7.2.0 to ≤ 7.2.1 | affected |
| 7.0.0 to ≤ 7.0.1 | affected | ||
FortiWebBrowse Fortinet / FortiWebDefault status: unaffected | CVE List, NVD | 7.2.0 to ≤ 7.2.1 | affected |
| 7.0.0 to ≤ 7.0.6 | affected | ||
| 6.4.0 to ≤ 6.4.2 | affected | ||
| 6.3.0 to ≤ 6.3.22 | affected | ||
| 6.2.0 to ≤ 6.2.7 | affected | ||
| 6.1.0 to ≤ 6.1.3 | affected |