CVE-2023-41842: Fortinet Fortianalyzer
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
Affected products
- Fortinet Fortianalyzer: from 6.2.0, before 7.0.10 (fixed in 7.0.10); from 7.2.0, before 7.2.4 (fixed in 7.2.4); from 7.4.0, before 7.4.2 (fixed in 7.4.2)
- Fortinet Fortianalyzer Big Data: from 6.4.5, up to and including 6.4.7; from 7.0.1, up to and including 7.0.6; from 7.2.0, before 7.2.6 (fixed in 7.2.6); version 6.2.5 only
- Fortinet FortiManager: from 6.2.0, before 7.0.10 (fixed in 7.0.10); from 7.2.0, before 7.2.4 (fixed in 7.2.4); from 7.4.0, before 7.4.2 (fixed in 7.4.2)
- Fortinet Fortiportal: from 5.3.0, before 6.0.15 (fixed in 6.0.15)
Published 2024-03-12. Last modified 2026-06-17.