CVE-2023-40721: Fortinet FortiOS

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

Affected products

  • Fortinet FortiOS: from 6.2.0, before 7.0.14 (fixed in 7.0.14); from 7.2.0, before 7.2.7 (fixed in 7.2.7); version 7.4.0 only
  • Fortinet Fortipam: from 1.0.0, before 1.2.0 (fixed in 1.2.0)
  • Fortinet FortiProxy: from 1.2.0, before 7.0.15 (fixed in 7.0.15); from 7.2.0, before 7.2.8 (fixed in 7.2.8); version 7.4.0 only
  • Fortinet Fortiswitchmanager: from 7.0.0, before 7.0.3 (fixed in 7.0.3); from 7.2.0, before 7.2.3 (fixed in 7.2.3)

Published 2025-02-11. Last modified 2026-06-17.