9 March 2023 [NO.TCSA : 20230309-1-1-P]
A critical vulnerability with CVSSv3 score of 9.3 (critical) has been discovered in FortiOS and FortiProxy administrative interfaces that could allow an attacker to execute arbitrary code or cause a denial of service (DoS) attack. The vulnerability, identified as CVE-2023-25610, is caused by a heap buffer underflow issue that occurs when processing user-supplied data.
TechCERT has observed a concerning trend among many organizations who keep their Fortinet administration portals open to the internet, despite this being a violation of recommended security best practices. Although there have been no reports of active exploitation of this vulnerability at this time, the risk of potential future exploits is significantly increased due to administrative portals are globally accessible from the internet.
The following versions of FortiOS and FortiProxy are affected by this vulnerability:
Fortinet has released patches to address this vulnerability:
Users are advised to test and update to the latest patched versions as soon as possible.
More Information