CVE-2023-33308: Fortinet FortiOS

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.

Affected products

  • Fortinet FortiOS: from 7.0.0, up to and including 7.0.10; from 7.2.0, up to and including 7.2.3
  • Fortinet FortiProxy: from 7.0.0, up to and including 7.0.9; version 7.2.0 only; version 7.2.1 only; version 7.2.2 only

Published 2023-07-26. Last modified 2026-06-17.