CVE-2023-33308: Fortinet FortiOS
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.
Affected products
- Fortinet FortiOS: from 7.0.0, up to and including 7.0.10; from 7.2.0, up to and including 7.2.3
- Fortinet FortiProxy: from 7.0.0, up to and including 7.0.9; version 7.2.0 only; version 7.2.1 only; version 7.2.2 only
Published 2023-07-26. Last modified 2026-06-17.