CVE-2023-40721

MEDIUM EPSS 14.2%
Published Feb 11, 20251y ago · Modified Jun 17, 20261w ago
6.7 CVSS 3.1
Medium
Find Similar
Published Feb 11, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

CVSS Details

Base Score
6.7
Exploitability
0.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
14.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-134

Affected Products 9

VendorProductVersionRange
fortinetfortios*≥6.2.0  –  <7.0.14
fortinetfortios*≥7.2.0  –  <7.2.7
fortinetfortios7.4.0any
fortinetfortiswitchmanager*≥7.0.0  –  <7.0.3
fortinetfortiswitchmanager*≥7.2.0  –  <7.2.3
fortinetfortiproxy*≥1.2.0  –  <7.0.15
fortinetfortiproxy*≥7.2.0  –  <7.2.8
fortinetfortiproxy7.4.0any
fortinetfortipam*≥1.0.0  –  <1.2.0

References 1

  • fortiguard.com https://fortiguard.com/psirt/FG-IR-23-261
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.