8.8
CVSSv3

CVE-2023-41678

Published: 13/12/2023 Updated: 15/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A double free in Fortinet FortiOS versions 7.0.0 up to and including 7.0.5, FortiPAM version 1.0.0 up to and including 1.0.3, 1.1.0 up to and including 1.1.1 allows malicious user to execute unauthorized code or commands via specifically crafted request.

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 7.0.0

fortinet fortios 7.0.1

fortinet fortios 7.0.2

fortinet fortipam 1.1.0

fortinet fortipam 1.0.0

fortinet fortipam 1.0.1

fortinet fortipam 1.0.2

fortinet fortipam 1.0.3

fortinet fortipam 1.1.1

fortinet fortios 7.0.3

fortinet fortios 7.0.4

fortinet fortios 7.0.5

Recent Articles

Final Patch Tuesday of 2023 goes out with a bang
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Microsoft fixed 36 flaws. Adobe addressed 212. Apple, Google, Cisco, VMware and Atlassian joined the party

It's the last Patch Tuesday of 2023, which calls for celebration – just as soon as you update Windows, Adobe, Google, Cisco, FortiGuard, SAP, VMware, Atlassian and Apple products, of course. Let's start with Apple, since two of the bugs Cupertino disclosed yesterday may have already been used for evil purposes.  While the fruit cart's December release fixes all the iThings, there's two especially concerning vulnerabilities in the WebKit (again) web browser engine that affect AppleTVs...