Format string error in FortiOS and FortiProxy - CVE-2022-43953
Published: June 13, 2023
Vulnerability identifier: #VU77182
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-43953
CWE-ID: CWE-134
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the device.
The vulnerability exists due to a format string error in fortiguard-resources CLI command. A local user can pass specially crafted argument to the affected CLI command and execute arbitrary code on the target system.
Affected software
FortiOS
FortiProxy
RUGGEDCOM APE1808
FortiProxy
RUGGEDCOM APE1808
How to mitigate CVE-2022-43953
Install updates from vendor's website.
FortiOS - addressed in versions 6.4.13, 7.0.12, 7.2.5
FortiProxy - addressed in versions 7.0.8, 7.2.2
FortiProxy - addressed in versions 7.0.8, 7.2.2