Format string error in Fortinet, Inc products - CVE-2023-41842

 

Format string error in Fortinet, Inc products - CVE-2023-41842

Published: March 14, 2024


Vulnerability identifier: #VU87527
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41842
CWE-ID: CWE-134
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a format string error. A local administrator can supply a specially crafted input that contains format string specifiers and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

FortiPortal
FortiAnalyzer
FortiManager
FortiAnalyzer-BigData

How to mitigate CVE-2023-41842

Install updates from vendor's website.

FortiPortal - update to 7.0.0
FortiAnalyzer - addressed in versions 7.0.10, 7.2.4, 7.4.2
FortiManager - addressed in versions 7.0.10, 7.2.4, 7.4.2
FortiAnalyzer-BigData - addressed in versions 7.2.6, 7.4.0

External References

Related Security Bulletins