CVE-2023-27997
Description
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
In plain language
AI Act nowCVE-2023-27997 is a critical SSL-VPN security flaw in FortiOS and FortiProxy that lets attackers run code over the network without needing a login; if your FortiOS/FortiProxy appliance has SSL-VPN reachable from the internet, you should act now.
CVE-2023-27997 is an unauthenticated remote code execution flaw in FortiOS SSL-VPN (and FortiProxy), caused by a heap-based buffer overflow triggered by specially crafted network requests; it is listed in CISA KEV as exploited in ransomware campaigns.
What to do now
- Check whether your FortiOS/FortiProxy device is running one of these affected versions: FortiOS 7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below; and FortiProxy 7.2.3 and below.
- Check whether SSL-VPN is enabled and reachable from untrusted networks (for example, the public internet).
- Upgrade to the fixed versions per vendor guidance: FortiOS 6K7K to 7.0.12 or above, 6.4.13 or above, 6.2.15 or above, or 6.0.17 or above.
- If you cannot upgrade immediately, disable SSL-VPN exposure and restrict access so it is not reachable from the internet, then schedule the upgrade as soon as possible.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Dayen-us·SecurityWeek· Exploited VeloCloud Orchestrator rce
- FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devicesen-us·Qualys Security Blog· Exploited FortiGate network-edge
- Operation Escaneo Signals Shift in LatAm Threat Landscapeen·Dark Reading· Research MexicanMafia data-breach
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-27997 and every CVE in our database. Create a free account — no credit card required.
Create Free Account