CVE-2023-27997

CRITICAL KEV RANSOMWARE

Fortinet Fortiproxy < 1.1.6 - Out-of-Bounds Write

Title source: rule

Description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

Exploits (11)

nomisec SCANNER 134 stars
by BishopFox · infoleak
https://github.com/BishopFox/CVE-2023-27997-check
nomisec WORKING POC 65 stars
by lexfo · remote
https://github.com/lexfo/xortigate-cve-2023-27997
nomisec WORKING POC 27 stars
by rio128128 · remote
https://github.com/rio128128/CVE-2023-27997-POC
nomisec WORKING POC 9 stars
by delsploit · remote
https://github.com/delsploit/CVE-2023-27997
nomisec SCANNER 2 stars
by TechinsightsPro · poc
https://github.com/TechinsightsPro/ShodanFortiOS
nomisec SCANNER 1 stars
by imbas007 · infoleak
https://github.com/imbas007/CVE-2023-27997-Check
nomisec SCANNER
by george1-adel · poc
https://github.com/george1-adel/CVE-2023-27997
nomisec WORKING POC
by onurkerembozkurt · remote
https://github.com/onurkerembozkurt/fgt-cve-2023-27997-exploit
nomisec WORKING POC
by node011 · remote
https://github.com/node011/CVE-2023-27997-POC
nomisec NO CODE
by Cyb3rEnthusiast · poc
https://github.com/Cyb3rEnthusiast/CVE-2023-27997
nomisec WORKING POC
by puckiestyle · dos
https://github.com/puckiestyle/cve-2023-27997

Scores

CVSS v3 9.8
EPSS 0.9084
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-06-13
VulnCheck KEV 2023-06-12
InTheWild.io 2023-06-13
ENISA EUVD EUVD-2023-31722
Ransomware Use Confirmed
CWE
CWE-122 CWE-787
Status published
Products (13)
fortinet/fortios 6.0.10
fortinet/fortios 6.2.4
fortinet/fortios 6.2.6
fortinet/fortios 6.2.7
fortinet/fortios 6.4.2
fortinet/fortios 6.4.6
fortinet/fortios 6.4.8
fortinet/fortios 6.4.10
fortinet/fortios 6.4.12
fortinet/fortios 7.0.5
... and 3 more
Published Jun 13, 2023
KEV Added Jun 13, 2023
Tracked Since Feb 18, 2026