← Back to browse · API

CVE-2023-33308

Severity
CRITICAL
CVSS
9.8
EPSS
0.02121
Risk score
39.94
CISA KEV
No
PoC
No
Published
2023-07-26
Modified
2024-10-23
First seen
2026-08-07
Aliases
EUVD-2023-37471, GHSA-H3GF-WHGG-WH93
Products
Fortinet:FortiOS 7.0.0 ≤7.0.10, Fortinet:FortiOS 7.2.0 ≤7.2.3, Fortinet:FortiProxy 7.0.0 ≤7.0.9, Fortinet:FortiProxy 7.2.0 ≤7.2.2
Sources
euvd EUVD-2023-37471

Description

A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.

References