CVE-2023-25602 is a stack-based buffer overflow vulnerability affecting multiple versions of Fortinet FortiWeb, including all 6.4 versions and earlier releases down to 5.6. This flaw allows an authenticated attacker to execute arbitrary code or commands by providing specially crafted command arguments. With a CVSS score of 7.8 (High), it poses a significant risk due to potential complete compromise of confidentiality, integrity, and availability, though it requires local access and low privileges. Currently, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.6.0, < 5.9.2CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.8CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.1.0, < 6.1.3CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.2.0, < 6.2.7CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.18CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.