CVE-2023-33302

MEDIUM

Fortinet FortiMail <6.4.4 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.

References (1)

Core 1
Core References

Scores

CVSS v3 4.7
EPSS 0.0036
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (2)
fortinet/fortimail 5.4.0 - 5.4.12
fortinet/fortindr 1.1.0 - 7.2.1
Published Mar 31, 2025
Tracked Since Feb 18, 2026