CVE-2024-23113
CRITICAL KEVFortinet FortiOS/FortiProxy/FortiPAM/FortiSwitchManager Format String Vulnerability via Crafted Packets
Title source: llmExploitation Summary
CVE-2024-23113 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 9, 2024. EIP tracks 8 public exploits from researchers including p33d, adminlove520, MAVRICK-1.
AI-analyzed exploit summary The repository contains a Python script that scans for CVE-2024-23113, a format string vulnerability in FortiGate's FGFM service on TCP port 541. It checks for vulnerability by sending a crafted payload and analyzing the SSL/TLS response, but does not include exploit code for RCE.
Description
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
Exploits (8)
The repository contains a Python script that scans for CVE-2024-23113, a format string vulnerability in FortiGate's FGFM service on TCP port 541. It checks for vulnerability by sending a crafted payload and analyzing the SSL/TLS response, but does not include exploit code for RCE.
The repository contains functional exploit code for CVE-2024-23113, including a server.py script and Docker setup for demonstration. The PoC leverages an authentication bypass vulnerability in TOTOLINK devices by manipulating the authCode parameter.
This repository provides a Docker-based test environment for validating CVE-2024-23113 Nuclei templates against simulated vulnerable FortiOS instances. It does not contain exploit code but simulates vulnerable endpoints for detection testing.
The repository contains a Python script that scans for CVE-2024-23113 by checking if FortiGate devices are vulnerable via a TLS-based format string payload. It does not exploit the vulnerability but detects potential exposure.
The repository contains a Python script that scans for CVE-2024-23113, a format string vulnerability in FortiGate's FGFM service on TCP port 541. It checks for vulnerability by sending a crafted payload and analyzing the server's response, but does not include functional exploit code for RCE.
The repository contains only a trivial 'Hello World' script and minimal README files with no functional exploit code or technical details about CVE-2024-23113.
The repository contains a functional Python script that exploits CVE-2024-23113, a format string vulnerability in the FortiGate FGFM service. The script sends a crafted request with a format string specifier (%n) to trigger the vulnerability, potentially leading to RCE or DoS.
The repository contains a Python script that checks for the presence of CVE-2024-23113 by sending a crafted packet to a target host and analyzing the SSL/TLS response. It does not exploit the vulnerability but detects potential susceptibility.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H