CVE-2023-27997 is a critical heap-based buffer overflow vulnerability (CWE-122) affecting FortiOS and FortiProxy SSL-VPN versions. A remote, unauthenticated attacker can exploit this flaw by sending specially crafted requests, potentially leading to arbitrary code execution or command injection. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction required, allowing for complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community discussion and media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.0, <= 1.1.6CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 1.2.0, <= 1.2.13CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 2.0.0, <= 2.0.12CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.9CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.3CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.